Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE
ID: e8451822-553b-5e53-87ab-55f551ea9a25
STIX ID: report--e8451822-553b-5e53-87ab-55f551ea9a25
Feed Name: Bleeping Computer
Threat Score
ProjectDiscovery disclosed three vulnerabilities in Versa Concerto — two critical flaws enabling authentication bypass and remote code execution (including an ld.so.preload RCE) and a high-severity Docker host write issue allowing full host compromise — provided PoCs and mitigation advice, and published details after a 90-day disclosure period; Versa later stated hotfixes and a GA release were made available and no exploitation was observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
