Known Vulnerabilities for products from Versa-networks
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Versa-networks".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-34290 json | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in... | Not Provided | 2025-12-20 | 2026-08-25 |
| CVE-2025-34027 json | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy confi... | Not Provided | 2025-05-21 | 2026-08-25 |
| CVE-2025-34025 json | The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability... | Not Provided | 2025-05-21 | 2026-08-25 |
| CVE-2025-24291 json | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java c... | Not Provided | 2025-06-19 | 2026-09-08 |
| CVE-2025-24288 json | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default crede... | Not Provided | 2025-06-19 | 2026-09-02 |
| CVE-2025-23173 json | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Direct... | Not Provided | 2025-06-19 | 2026-09-08 |
| CVE-2025-23172 json | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoi... | Not Provided | 2025-06-19 | 2026-09-03 |
| CVE-2025-23171 json | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does... | Not Provided | 2025-06-19 | 2026-08-25 |
| CVE-2025-23170 json | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Direc... | Not Provided | 2025-06-19 | 2026-09-03 |
| CVE-2025-23169 json | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, an... | Not Provided | 2025-06-19 | 2026-09-03 |
| CVE-2024-45229 json | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, bann... | Not Provided | 2024-09-20 | 2026-08-25 |
| CVE-2024-42450 json | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availab... | Not Provided | 2024-11-19 | 2026-09-03 |
| CVE-2021-39285 json | A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface ... | 6.1 - MEDIUM | 2021-09-07 | 2021-09-09 |
| CVE-2019-25030 json | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key der... | 5.5 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2019-25029 json | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operat... | Not Provided | 2021-05-26 | 2026-08-31 |
| CVE-2018-16499 json | In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the se... | 5.9 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2018-16498 json | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuratio... | 5.5 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2018-16497 json | In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the serv... | Not Provided | 2021-05-26 | 2026-08-31 |
| CVE-2018-16496 json | In Versa Director, the un-authentication request found. | 5.3 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2018-16495 json | In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed aft... | 8.8 - HIGH | 2021-05-26 | 2021-06-04 |