ZeroHour

CVE-2025-34027

PoC niche

Unauthenticated RCE in Versa Concerto via Auth Bypass and TOCTOU Race

CVSS 4.0
10.0 critical
EPSS
45%p99
Published
()
Modified
AI analysis

Versa Concerto, Versa Networks' SD-WAN orchestration platform, mishandles authentication in its Traefik reverse proxy configuration, allowing unauthenticated attackers to reach administrative endpoints. By chaining this bypass with the Spack upload endpoint, an attacker can trigger a time-of-check to time-of-use (TOCTOU) file write combined with a race condition to manipulate path loading and achieve remote code execution without any credentials. Successful exploitation gives the attacker code execution on the Concerto server, with related coverage warning the flaws could let attackers escape the Docker container and compromise the underlying host (CVSS 4.0 score 10.0, critical). Concerto versions 12.1.2 through 12.2.0 are known to be affected, and additional versions may also be vulnerable, so any internet-exposed or broadly reachable Concerto deployment is at risk. A public proof-of-concept walkthrough has been published, the flaw sits in the 99th EPSS percentile with a 45.2% probability of exploitation within 30 days, and it is not yet on CISA's KEV list.

What to do: Upgrade Concerto to a release beyond 12.2.0 as directed by Versa's advisory, since additional versions may also be affected. Until patched, restrict access to Concerto's portal/administrative endpoints and the Spack upload endpoint to trusted management networks only, and review access logs for unauthenticated requests to administrative endpoints. Because exploitation involves a timing-based race, network-level access restriction is the most reliable interim mitigation.

Affected
Versa Networks Concerto12.1.2 through 12.2.0 (additional versions may be vulnerable)
Estimated exposure
nichelikely hundreds to low thousands of deployed instances, of which an unknown subset is internet-exposed — Concerto is a niche enterprise/service-provider SD-WAN orchestration and management platform typically deployed once per enterprise or tenant rather than at consumer scale, so affected deployments plausibly number in the hundreds to low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race condition to achieve remote code execution via path loading manipulation, allowing an unauthenticated actor to achieve remote code execution (RCE).This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

Vendors
versa-networks
Products
concerto
Weakness
CWE-367
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news