U.S. CISA adds Versa Director bug to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-39717 | Unrestricted File Upload in Versa Networks Versa Director Exploited by Volt Typhoon CVE-2024-39717 is an unrestricted file upload flaw (CWE-434) in the interface customization function of Versa Networks' Versa Director: the 'Change Favicon' option in the GUI accepts an uploaded file that merely ends in a .png extension, so a malicious file can masquerade as an image. Exploitation requires network access to the Director GUI and valid credentials for a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin account (tenant-level users cannot reach the feature), which is why the 7.2 CVSS score includes 'high privileges required.' By planting a dangerous file disguised as a .png, an attacker gains a code-execution path on the Director server consistent with the flaw's high confidentiality, integrity and availability impact ratings. Any organization running Versa Director — particularly service providers and internet providers whose management interface is reachable from the internet — is potentially affected. Exploitation is confirmed in the wild: China-linked actor Volt Typhoon used the flaw as a zero-day against U.S. and global IT targets, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-23, and federal agencies were urged to patch by September 2024. Do: Apply Versa Networks' fix/mitigation instructions — CISA's required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable — and meet the September 2024 federal remediation deadline if applicable. Restrict access to the Versa Director GUI to trusted management networks rather than exposing it to the internet, and audit and rotate credentials for Provider-Data-Center-Admin and Provider-Data-Center-System-Admin accounts, since the observed Volt Typhoon activity relied on valid high-privilege logins. Check Director systems for unexpected files uploaded through the Change Favicon feature that may be disguised as .png images. | 7.2 | 4% | KEV |
| moderate≈ low thousands of Versa Director deployments worldwide, of which only a small fraction are internet-exposed |
Full article262 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Versa Director bug to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Versa Director Dangerous File Type Upload Vulnerability CVE-2024-39717 (CVSS score: 6.6) to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability CVE-2024-39717 resides in the “Change Favicon” feature in Versa Director’s GUI, it allows administrators with specific privileges to upload a malicious file disguised as a PNG image. Exploitation requires successful authentication by a user with the necessary privileges. Although details are limited, Versa Networks confirmed one case where the vulnerability was exploited due to a customer’s failure to implement recommended firewall guidelines. This oversight allowed the attacker to exploit the vulnerability without needing to access the GUI.
” Versa Networks is aware of one confirmed customer reported instance where this vulnerability was exploited because the Firewall guidelines which were published in 2015 & 2017 were not implemented by that customer.” reads the advisory. “This non-implementation resulted in the bad actor being able to exploit this vulnerability without using the GUI.”
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by September 13, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167534/hacking/cisa-adds-versa-director-bug-known-exploited-vulnerabilities-catalog.html