Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-39717 Details

Description

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Versa Director Dangerous File Type Upload VulnerabilityAug 23, 2024Sep 13, 2024Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-434Unrestricted Upload of File with Dangerous Type[email protected]
CWE-434Unrestricted Upload of File with Dangerous TypeCISA-ADP

Affected Products

ProductVersions
versa-networks versa director
21.2.2
21.2.3
22.1.1
22.1.2
22.1.3

CPE

  • cpe:2.3:a:versa-networks:versa_director:21.2.2:*:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:21.2.3:*:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.2:*:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-39717
NVD Published Date:
Aug 22, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-39717 Details - Not Deferred