Versa Director
cpe:2.3:a:versa-networks:versa_director:*:*:*:*:*:*:*
- 22.1.4
- 22.1.3
- 22.1.2
- 22.1.1
- 21.2.3
- 21.2.2
A vulnerability in the Versa Director SD-WAN orchestration platform's Webhook feature allows authenticated users to send crafted HTTP requests to localhost. This exploitation can execute commands as the versa user, who has sudo privileges, potentially leading to privilege escalation or remote code execution. The vulnerability affects Versa Director versions 22.1.4 (prior to February 8, 2025), 22.1.3 (all), 22.1.2 (all), 22.1.1 (all), 21.2.3 (all), and 21.2.2 (all).
Exploitation of this vulnerability could result in unauthorized privilege escalation or remote code execution on the affected system.
Users are advised to upgrade to Versa Director versions 22.1.4 (February 8, 2025 and later), 22.1.3 (June 10, 2025 and later), 22.1.2 (June 10, 2025 and later), or 21.2.3 (June 10, 2025 and later).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.