Known Vulnerabilities for products from Versa-networks
Listed below are 14 of the newest known vulnerabilities associated with the vendor "Versa-networks".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-34290 json | Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in... | Not Provided | 2025-12-20 | 2026-08-25 |
| CVE-2025-34027 json | The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy confi... | Not Provided | 2025-05-21 | 2026-08-25 |
| CVE-2025-34025 json | The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability... | Not Provided | 2025-05-21 | 2026-08-25 |
| CVE-2025-23171 json | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does... | Not Provided | 2025-06-19 | 2026-08-25 |
| CVE-2024-45229 json | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, bann... | Not Provided | 2024-09-20 | 2026-08-25 |
| CVE-2021-39285 json | A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface ... | 6.1 - MEDIUM | 2021-09-07 | 2021-09-09 |
| CVE-2019-25030 json | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key der... | 5.5 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2019-25029 json | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operat... | 9.8 - CRITICAL | 2021-05-26 | 2021-06-07 |
| CVE-2018-16499 json | In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the se... | 5.9 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2018-16498 json | In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuratio... | 5.5 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2018-16497 json | In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the serv... | 7.8 - HIGH | 2021-05-26 | 2021-06-07 |
| CVE-2018-16496 json | In Versa Director, the un-authentication request found. | 5.3 - MEDIUM | 2021-05-26 | 2021-06-07 |
| CVE-2018-16495 json | In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed aft... | 8.8 - HIGH | 2021-05-26 | 2021-06-04 |
| CVE-2018-16494 json | In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecur... | 8.8 - HIGH | 2021-05-26 | 2021-06-04 |