LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-39717: Versa Director Dangerous File Type Upload Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 23, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 13, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-39717 to its Known Exploited Vulnerabilities catalog on Aug 23, 2024, with a federal patch deadline of Sep 13, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin…

CVE-2024-39717 is an unrestricted file upload vulnerability in the Versa Director graphical user interface. It allows administrators holding Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to abuse the “Change Favicon” feature, which is intended to accept a .png image for interface customization. An attacker who already possesses those privileges can upload a malicious file that carries a .png extension and is presented as an image. Because Versa Director is a central management component for network infrastructure, successful abuse can give an adversary a foothold for further actions inside the management plane. Exact affected releases and any additional constraints must be confirmed against the vendor advisory.

How it works

The underlying weakness is CWE-434: unrestricted upload of a file with a dangerous type. The Versa Director GUI exposes a favicon-upload path that performs insufficient validation of the content being submitted. An administrator with the stated elevated roles can supply a file whose name ends in .png yet whose payload is not a benign image. Once the file is stored and later processed or served by the application, the malicious content can execute or be used as a staging point for additional attacker activity. No public exploit mechanics beyond this description are provided here; defenders should treat any unexpected favicon upload as potentially hostile and verify details in the vendor advisory.

Am I affected? How to find it in your systems

Versa Director is typically deployed as the centralized orchestration and management platform for Versa SD-WAN and related network services. It commonly runs on dedicated management servers or virtual appliances inside data-center or cloud environments that administer provider or enterprise networks.

How to remediate

Apply the mitigations or software updates supplied by the vendor as the primary remediation step. CISA directs organizations to follow the vendor’s instructions or to discontinue use of the product if mitigations are unavailable. After patching, re-validate that the Change Favicon upload path now enforces strict content-type and content-inspection checks.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit both the ability to reach the upload function and the impact of a successful upload.

If your data may have been exposed

Although ransomware use of this specific vulnerability is not documented, any unrestricted-upload flaw that can be reached by privileged accounts can serve as an initial access or persistence vector leading to broader compromise. If you suspect the vulnerability has been abused, treat the Versa Director host and any systems it manages as potentially compromised: isolate the host, preserve forensic images, rotate credentials, and review configuration and traffic logs for unauthorized changes. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether associated credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVersa · Director
WeaknessCWE-434
Added to CISA KEVAug 23, 2024
Federal patch deadlineSep 13, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities