CVE-2025-24291 (GCVE-0-2025-24291)
Vulnerability from cvelistv5
Published
2025-06-18 23:30
Modified
2025-06-23 16:04
Severity ?
VLAI Severity ?
EPSS score ?
Summary
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk.
Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers.
There are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.
References
Impacted products
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-24291", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-06-23T15:45:48.843611Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-74", "description": "CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-06-23T16:04:49.558Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "Director", "vendor": "Versa", "versions": [ { "lessThanOrEqual": "21.2.2", "status": "affected", "version": "21.2.2", "versionType": "semver" }, { "lessThanOrEqual": "21.2.3", "status": "affected", "version": "21.2.3", "versionType": "semver" }, { "lessThanOrEqual": "22.1.1", "status": "affected", "version": "22.1.1", "versionType": "semver" }, { "lessThanOrEqual": "22.1.2", "status": "affected", "version": "22.1.2", "versionType": "semver" }, { "lessThanOrEqual": "22.1.3", "status": "affected", "version": "22.1.3", "versionType": "semver" }, { "lessThanOrEqual": "22.1.4", "status": "affected", "version": "22.1.4", "versionType": "semver" } ] } ], "descriptions": [ { "lang": "en", "value": "The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk. \r\n\r\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. \r\n\r\nThere are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions." } ], "metrics": [ { "cvssV3_1": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" } } ], "providerMetadata": { "dateUpdated": "2025-06-18T23:30:54.681Z", "orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1", "shortName": "hackerone" }, "references": [ { "url": "https://security-portal.versa-networks.com/emailbulletins/68526fc6dc94d6b9f2faf71d" }, { "url": "https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4" }, { "url": "https://support.versa-networks.com/support/solutions/articles/23000026033-release-22-1-3" }, { "url": "https://support.versa-networks.com/support/solutions/articles/23000025680-release-22-1-2" }, { "url": "https://support.versa-networks.com/support/solutions/articles/23000024323-release-21-2-3" } ] } }, "cveMetadata": { "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1", "assignerShortName": "hackerone", "cveId": "CVE-2025-24291", "datePublished": "2025-06-18T23:30:54.681Z", "dateReserved": "2025-01-17T01:00:07.458Z", "dateUpdated": "2025-06-23T16:04:49.558Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2025-24291\",\"sourceIdentifier\":\"support@hackerone.com\",\"published\":\"2025-06-19T00:15:22.437\",\"lastModified\":\"2025-06-23T20:16:59.783\",\"vulnStatus\":\"Awaiting Analysis\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk. \\r\\n\\r\\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. \\r\\n\\r\\nThere are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.\"},{\"lang\":\"es\",\"value\":\"La plataforma de orquestaci\u00f3n Versa Director SD-WAN permite cargar diversos tipos de archivos. Sin embargo, el c\u00f3digo Java que gestiona la carga de archivos contiene una vulnerabilidad de inyecci\u00f3n de argumentos. Al a\u00f1adir argumentos adicionales al nombre del archivo, un atacante puede eludir la validaci\u00f3n de tipo MIME, lo que permite cargar archivos de cualquier tipo. Esta vulnerabilidad puede explotarse para almacenar un archivo malicioso en el disco. Versa Networks no tiene constancia de ning\u00fan caso reportado de explotaci\u00f3n de esta vulnerabilidad. Investigadores de seguridad externos han divulgado una prueba de concepto de esta vulnerabilidad. No existen soluciones alternativas para desactivar la opci\u00f3n de interfaz gr\u00e1fica de usuario (GUI). Versa recomienda actualizar Director a una de las versiones de software corregidas.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"support@hackerone.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N\",\"baseScore\":6.1,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"HIGH\",\"userInteraction\":\"REQUIRED\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":0.9,\"impactScore\":5.2}]},\"weaknesses\":[{\"source\":\"134c704f-9b21-4f2e-91b3-4a467353bcc0\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-74\"}]}],\"references\":[{\"url\":\"https://security-portal.versa-networks.com/emailbulletins/68526fc6dc94d6b9f2faf71d\",\"source\":\"support@hackerone.com\"},{\"url\":\"https://support.versa-networks.com/support/solutions/articles/23000024323-release-21-2-3\",\"source\":\"support@hackerone.com\"},{\"url\":\"https://support.versa-networks.com/support/solutions/articles/23000025680-release-22-1-2\",\"source\":\"support@hackerone.com\"},{\"url\":\"https://support.versa-networks.com/support/solutions/articles/23000026033-release-22-1-3\",\"source\":\"support@hackerone.com\"},{\"url\":\"https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4\",\"source\":\"support@hackerone.com\"}]}}", "vulnrichment": { "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2025-24291\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-06-23T15:45:48.843611Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-74\", \"description\": \"CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component (\u0027Injection\u0027)\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-06-23T15:45:49.800Z\"}}], \"cna\": {\"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 6.1, \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N\"}}], \"affected\": [{\"vendor\": \"Versa\", \"product\": \"Director\", \"versions\": [{\"status\": \"affected\", \"version\": \"21.2.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"21.2.2\"}, {\"status\": \"affected\", \"version\": \"21.2.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"21.2.3\"}, {\"status\": \"affected\", \"version\": \"22.1.1\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"22.1.1\"}, {\"status\": \"affected\", \"version\": \"22.1.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"22.1.2\"}, {\"status\": \"affected\", \"version\": \"22.1.3\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"22.1.3\"}, {\"status\": \"affected\", \"version\": \"22.1.4\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"22.1.4\"}], \"defaultStatus\": \"unaffected\"}], \"references\": [{\"url\": \"https://security-portal.versa-networks.com/emailbulletins/68526fc6dc94d6b9f2faf71d\"}, {\"url\": \"https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4\"}, {\"url\": \"https://support.versa-networks.com/support/solutions/articles/23000026033-release-22-1-3\"}, {\"url\": \"https://support.versa-networks.com/support/solutions/articles/23000025680-release-22-1-2\"}, {\"url\": \"https://support.versa-networks.com/support/solutions/articles/23000024323-release-21-2-3\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk. \\r\\n\\r\\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. \\r\\n\\r\\nThere are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.\"}], \"providerMetadata\": {\"orgId\": \"36234546-b8fa-4601-9d6f-f4e334aa8ea1\", \"shortName\": \"hackerone\", \"dateUpdated\": \"2025-06-18T23:30:54.681Z\"}}}", "cveMetadata": "{\"cveId\": \"CVE-2025-24291\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-06-23T16:04:49.558Z\", \"dateReserved\": \"2025-01-17T01:00:07.458Z\", \"assignerOrgId\": \"36234546-b8fa-4601-9d6f-f4e334aa8ea1\", \"datePublished\": \"2025-06-18T23:30:54.681Z\", \"assignerShortName\": \"hackerone\"}", "dataType": "CVE_RECORD", "dataVersion": "5.1" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…