CVE-2024-39717
Versa Director Dangerous File Type Upload Vulnerability
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege).
The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
HIGH · CVSS 7.2
⚠ CISA KEV
EPSS 0.05357
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- EPSS percentile: top 10% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules10
YARA rules0