Record summary

CVE-2024-39717 has a selected CVSS score of 7.2 (high). CISA lists CVE-2024-39717 in KEV.

Description

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Aug 23, 2024 · CISA
VulnCheck KEV
Listed · Aug 23, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CISA, CVE List21.2.2 to ≤ 21.2.2affected
21.2.3 before 2024-06-21 to < 21.2.3 before 2024-06-21affected
22.1.1 to ≤ 22.1.1affected
22.1.2 before 2024-06-21 to ≤ 22.1.2 before 2024-06-21affected
22.1.3 before 2024-06-21 to ≤ 22.1.3 before 2024-06-21affected

Default status: unaffected

CVE List21.2.2affected
21.2.3 to < 21.2.3_2024-06-21affected
22.1.1affected
22.1.2 to < 22.1.2_2024-06-21affected
22.1.3 to < 22.1.3_2024-06-21affected

References

7