versa-networks kayıtları
versa-networks üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %8,3
- Silahlaştırılmış
- 2 · %8,3
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %4,2
- Yayından KEV’e ortanca
- 124 gün
Tekrar eden sınıflar
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-250 Execution with Unnecessary Privileges1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
- CWE-290 Authentication Bypass by Spoofing1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
91Hemen | CVE-2025-34026Silahlaştırılmış | Versa Concerto Actuator Authentication Bypass Information Leakversa-networks · concerto · CWE-288 | Kritik9,2 | KEV | %81,9 | 21 May 2025 |
59Planlayın | CVE-2024-39717Silahlaştırılmış | The Versa Director GUI provides an option to customize the look and feel of the user interface.versa-networks · versa director · CWE-434 | Yüksek7,2 | KEV | %4,0 | 22 Ağu 2024 |
54Planlayın | CVE-2025-34027Kavram kanıtı | Versa Concerto Authentication Bypass File Write Remote Code Executionversa-networks · concerto · CWE-367 | Kritik10,0 | — | %45,2 | 21 May 2025 |
40Planlayın | CVE-2019-25029İstismar yok | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via versa-networks · versa director · CWE-77 | Kritik9,8 | — | %2,4 | 26 May 2021 |
40Planlayın | CVE-2024-42450İstismar yok | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data.versa-networks · versa director · CWE-798 | Kritik10,0 | — | %0,6 | 19 Kas 2024 |
39İzleyin | CVE-2025-24288İstismar yok | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multversa-networks · versa director · CWE-1188 | Kritik9,8 | — | %0,5 | 18 Haz 2025 |
36İzleyin | CVE-2018-16494İstismar yok | In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissiversa-networks · versa operating system · CWE-377 | Yüksek8,8 | — | %1,9 | 26 May 2021 |
35İzleyin | CVE-2018-16495İstismar yok | In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user sucversa-networks · versa operating system · CWE-384 | Yüksek8,8 | — | %0,9 | 26 May 2021 |
35İzleyin | CVE-2025-23168İstismar yok | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via emaversa-networks · versa director · CWE-290 | Yüksek8,8 | — | %0,4 | 18 Haz 2025 |
34İzleyin | CVE-2025-34025İstismar yok | Versa Concerto Insecure Docker Mount Container Escapeversa-networks · concerto · CWE-732 | Yüksek8,6 | — | %0,6 | 21 May 2025 |
34İzleyin | CVE-2025-34290İstismar yok | Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalationversa-networks · sase client · CWE-250 | Yüksek8,5 | — | %0,1 | 20 Ara 2025 |
31İzleyin | CVE-2018-16497İstismar yok | In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server.versa-networks · versa analytics · CWE-269 | Yüksek7,8 | — | %0,2 | 26 May 2021 |
30İzleyin | CVE-2025-23173İstismar yok | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI.versa-networks · versa director · CWE-200 | Yüksek7,5 | — | %0,6 | 18 Haz 2025 |
28İzleyin | CVE-2025-23172İstismar yok | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints.versa-networks · versa director · CWE-918 | Yüksek7,2 | — | %1,1 | 18 Haz 2025 |
28İzleyin | CVE-2025-23171İstismar yok | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files.versa-networks · versa director · CWE-434 | Yüksek7,2 | — | %0,6 | 18 Haz 2025 |
26İzleyin | CVE-2025-23170İstismar yok | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Sversa-networks · versa director · CWE-77 | Orta6,7 | — | %0,6 | 18 Haz 2025 |
26İzleyin | CVE-2024-45229İstismar yok | The Versa Director offers REST APIs for orchestration and management.versa-networks · versa director · CWE-306 | Orta6,6 | — | %0,5 | 20 Eyl 2024 |
24İzleyin | CVE-2021-39285İstismar yok | A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8.versa-networks · versa director · CWE-79 | Orta6,1 | — | %0,8 | 7 Eyl 2021 |
24İzleyin | CVE-2025-23169İstismar yok | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo.versa-networks · versa director · CWE-79 | Orta6,1 | — | %0,4 | 18 Haz 2025 |
24İzleyin | CVE-2025-24291İstismar yok | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files.versa-networks · versa director · CWE-74 | Orta6,1 | — | %0,4 | 18 Haz 2025 |
23İzleyin | CVE-2018-16499İstismar yok | In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using manversa-networks · versa operating system · CWE-326 | Orta5,9 | — | %0,3 | 26 May 2021 |
22İzleyin | CVE-2019-25030İstismar yok | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation functioversa-networks · versa analytics · CWE-522 | Orta5,5 | — | %0,2 | 26 May 2021 |
22İzleyin | CVE-2018-16498İstismar yok | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files.versa-networks · versa director · CWE-312 | Orta5,5 | — | %0,2 | 26 May 2021 |
21İzleyin | CVE-2018-16496İstismar yok | In Versa Director, the un-authentication request found.versa-networks · versa director · CWE-287 | Orta5,3 | — | %0,7 | 26 May 2021 |
- CVE-2025-3402691Hemen
Versa Concerto Actuator Authentication Bypass Information Leak
KritikCVSS 9,2KEVSilahlaştırılmışEPSS %82versa-networks · concerto21 May 2025
- CVE-2024-3971759Planlayın
The Versa Director GUI provides an option to customize the look and feel of the user interface.
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %4versa-networks · versa director22 Ağu 2024
- CVE-2025-3402754Planlayın
Versa Concerto Authentication Bypass File Write Remote Code Execution
KritikCVSS 10,0Kavram kanıtıEPSS %45versa-networks · concerto21 May 2025
- CVE-2019-2502940Planlayın
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via
KritikCVSS 9,8İstismar yokEPSS %2versa-networks · versa director26 May 2021
- CVE-2024-4245040Planlayın
The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data.
KritikCVSS 10,0İstismar yokEPSS %1versa-networks · versa director19 Kas 2024
- CVE-2025-2428839İzleyin
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and mult
KritikCVSS 9,8İstismar yokEPSS %0versa-networks · versa director18 Haz 2025
- CVE-2018-1649436İzleyin
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissi
YüksekCVSS 8,8İstismar yokEPSS %2versa-networks · versa operating system26 May 2021
- CVE-2018-1649535İzleyin
In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user suc
YüksekCVSS 8,8İstismar yokEPSS %1versa-networks · versa operating system26 May 2021
- CVE-2025-2316835İzleyin
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via ema
YüksekCVSS 8,8İstismar yokEPSS %0versa-networks · versa director18 Haz 2025
- CVE-2025-3402534İzleyin
Versa Concerto Insecure Docker Mount Container Escape
YüksekCVSS 8,6İstismar yokEPSS %1versa-networks · concerto21 May 2025
- CVE-2025-3429034İzleyin
Versa SASE Client for Windows < 7.9.5 Arbitrary Folder Deletion Leading to Local Privilege Escalation
YüksekCVSS 8,5İstismar yokEPSS %0versa-networks · sase client20 Ara 2025
- CVE-2018-1649731İzleyin
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server.
YüksekCVSS 7,8İstismar yokEPSS %0versa-networks · versa analytics26 May 2021
- CVE-2025-2317330İzleyin
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI.
YüksekCVSS 7,5İstismar yokEPSS %1versa-networks · versa director18 Haz 2025
- CVE-2025-2317228İzleyin
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints.
YüksekCVSS 7,2İstismar yokEPSS %1versa-networks · versa director18 Haz 2025
- CVE-2025-2317128İzleyin
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files.
YüksekCVSS 7,2İstismar yokEPSS %1versa-networks · versa director18 Haz 2025
- CVE-2025-2317026İzleyin
The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via S
OrtaCVSS 6,7İstismar yokEPSS %1versa-networks · versa director18 Haz 2025
- CVE-2024-4522926İzleyin
The Versa Director offers REST APIs for orchestration and management.
OrtaCVSS 6,6İstismar yokEPSS %1versa-networks · versa director20 Eyl 2024
- CVE-2021-3928524İzleyin
A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8.
OrtaCVSS 6,1İstismar yokEPSS %1versa-networks · versa director7 Eyl 2021
- CVE-2025-2316924İzleyin
The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo.
OrtaCVSS 6,1İstismar yokEPSS %0versa-networks · versa director18 Haz 2025
- CVE-2025-2429124İzleyin
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files.
OrtaCVSS 6,1İstismar yokEPSS %0versa-networks · versa director18 Haz 2025
- CVE-2018-1649923İzleyin
In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man
OrtaCVSS 5,9İstismar yokEPSS %0versa-networks · versa operating system26 May 2021
- CVE-2019-2503022İzleyin
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation functio
OrtaCVSS 5,5İstismar yokEPSS %0versa-networks · versa analytics26 May 2021
- CVE-2018-1649822İzleyin
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files.
OrtaCVSS 5,5İstismar yokEPSS %0versa-networks · versa director26 May 2021
- CVE-2018-1649621İzleyin
In Versa Director, the un-authentication request found.
OrtaCVSS 5,3İstismar yokEPSS %1versa-networks · versa director26 May 2021