logo

Versa fixes Director zero-day vulnerability exploited in attacks

ID: 25946b44-6d97-578c-b094-1bd26e6ec1db

STIX ID: report--25946b44-6d97-578c-b094-1bd26e6ec1db

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-08-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Versa Networks patched a high-severity zero-day (CVE-2024-39717) in Versa Director that allowed users with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to upload malicious files disguised as PNGs via the 'Change Favicon' feature; the flaw was exploited in the wild by an APT actor at least once. Versa and CISA urge customers to implement long-standing system hardening and firewall guidance, upgrade impacted Director installations, and inspect /var/versa/vnms/web/custom_logo/ for suspicious uploads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.