VulnSea

versa-networks has 5 CVEs on record between 2021 and 2025. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: versa_director (4), versa_analytics (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
0 prev 0

Products

  • versa_director 4
  • versa_analytics 1
5
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

versa-networks vulnerabilities

CVEs affecting versa-networks, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2025-24291Medium· 6.1
1y ago

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the…

Sunlitversa-networks · versa_directorEPSS 0.38%via NVD
CVE-2025-23173High· 7.5
1y ago

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI

The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposu…

Twilightversa-networks · versa_directorEPSS 0.62%via NVD
CVE-2025-24288Critical· 9.8
1y ago

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Vers…

Midnightversa-networks · versa_directorEPSS 0.47%via NVD
CVE-2019-25029Critical· 9.8
5y ago

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsaf…

Midnightversa-networks · versa_directorEPSS 2.7%via NVD
CVE-2018-16497High· 7.8
5y ago

In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server

In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, t…

Twilightversa-networks · versa_analyticsEPSS 0.23%via NVD
versa-networks vulnerabilities (CVEs) · VulnSea