CVE-2024-39717
Versa Director Dangerous File Type Upload Vulnerability
Record summary
CVE-2024-39717 has a selected CVSS score of 7.2 (high). CISA lists CVE-2024-39717 in KEV.
Description
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Aug 23, 2024 · CISA
- VulnCheck KEV
- Listed · Aug 23, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 4, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DirectorBrowse Versa / DirectorDefault status: unaffected | CISA, CVE List | 21.2.2 to ≤ 21.2.2 | affected |
| 21.2.3 before 2024-06-21 to < 21.2.3 before 2024-06-21 | affected | ||
| 22.1.1 to ≤ 22.1.1 | affected | ||
| 22.1.2 before 2024-06-21 to ≤ 22.1.2 before 2024-06-21 | affected | ||
| 22.1.3 before 2024-06-21 to ≤ 22.1.3 before 2024-06-21 | affected | ||
versa_directorBrowse versa-networks / versa_directorDefault status: unaffected | CVE List | 21.2.2 | affected |
| 21.2.3 to < 21.2.3_2024-06-21 | affected | ||
| 22.1.1 | affected | ||
| 22.1.2 to < 22.1.2_2024-06-21 | affected | ||
| 22.1.3 to < 22.1.3_2024-06-21 | affected |