Versa Director
cpe:2.3:a:versa-networks:versa_director:*:*:*:*:*:*:*
- 22.1.4
- 22.1.3
- 22.1.2
- 21.2.3
A vulnerability in the Versa Director SD-WAN orchestration platform allows authenticated attackers to upload web shells via an insecure UCPE image upload. The platform improperly restricts file upload permissions, enabling uploads even when the user interface suggests otherwise. Additionally, Versa Director reveals the full filenames of uploaded temporary files, including UUID prefixes.
Successful exploitation allows authenticated attackers to upload web shells, which could be used to execute arbitrary commands on the server.
Users are advised to upgrade to Versa Director versions 22.1.4 (February 8th Hot Fix), 22.1.3 (June 10, 2025, and later), 22.1.2 (June 10, 2025, and later), or 21.2.3 (June 10, 2025, and later).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.