ZeroHour

CVE-2024-39717

KEVmoderate1

Unrestricted File Upload in Versa Networks Versa Director Exploited by Volt Typhoon

CISA: Versa Director Dangerous File Type Upload Vulnerability

CVSS 3.1
7.2 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2024-39717 is an unrestricted file upload flaw (CWE-434) in the interface customization function of Versa Networks' Versa Director: the 'Change Favicon' option in the GUI accepts an uploaded file that merely ends in a .png extension, so a malicious file can masquerade as an image. Exploitation requires network access to the Director GUI and valid credentials for a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin account (tenant-level users cannot reach the feature), which is why the 7.2 CVSS score includes 'high privileges required.' By planting a dangerous file disguised as a .png, an attacker gains a code-execution path on the Director server consistent with the flaw's high confidentiality, integrity and availability impact ratings. Any organization running Versa Director — particularly service providers and internet providers whose management interface is reachable from the internet — is potentially affected. Exploitation is confirmed in the wild: China-linked actor Volt Typhoon used the flaw as a zero-day against U.S. and global IT targets, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-23, and federal agencies were urged to patch by September 2024.

What to do: Apply Versa Networks' fix/mitigation instructions — CISA's required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable — and meet the September 2024 federal remediation deadline if applicable. Restrict access to the Versa Director GUI to trusted management networks rather than exposing it to the internet, and audit and rotate credentials for Provider-Data-Center-Admin and Provider-Data-Center-System-Admin accounts, since the observed Volt Typhoon activity relied on valid high-privilege logins. Check Director systems for unexpected files uploaded through the Change Favicon feature that may be disguised as .png images.

Affected
Versa Networks Versa Director
Estimated exposure
moderate≈ low thousands of Versa Director deployments worldwide, of which only a small fraction are internet-exposed — Versa Director is the management/orchestration component of Versa's SD-WAN platform sold mainly to service providers and large enterprises (a market of several thousand customer deployments rather than consumer scale), and the targeted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

CISA Known Exploited Vulnerability
Affected
Versa Director
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
versa-networks
Products
versa director
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news