Executive brief
The Versa Director GUI allows authenticated administrators with high-level privileges to upload malicious files disguised with a .png extension via the 'Change Favicon' feature. This unrestricted upload of a dangerous file type can lead to arbitrary code execution if the file is subsequently processed or executed by the system.
Affected products
- Versa Networks Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3
Timeline
- 2024-08-23: disclosed: CVE published and added to CISA KEV catalog
- 2024-08-23: kev added
- 2024-08-27: exploited: Vendor confirmed at least one instance of exploitation in the wild due to non-implementation of firewall guidelines.