CVE-2024-45208 Details
Description
The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versions of Versa Director bound to these ports on all interfaces. An attacker that can access the Versa Director could access the NCS service on port 4566 and exploit it to perform unauthorized administrative actions and perform remote code execution. Customers are recommended to follow the hardening guide. Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers.
A critical remote code execution vulnerability has been identified in the Versa Director SD-WAN orchestration platform, specifically in versions 22.1.1, 22.1.2, 22.1.3, and 21.2.2. This vulnerability arises from the application's use of Cisco NCS application service, where Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versions of Versa Director are bound to these ports on all interfaces. An attacker with access to the Versa Director could exploit the NCS service on port 4566 to perform unauthorized administrative actions and execute remote code.
Users are advised to update to Versa Director version 22.1.4 or later. For versions 22.1.1, 22.1.2, 22.1.3, and 21.2.2, it is recommended to follow the Versa Director hardening guide to mitigate the vulnerability. After hardening, ensure to reset passwords for all users, both local and external, if external authentication was configured.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 19, 2025CISA-ADP
Assessed Jun 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Versa Director | >= 22.1.4, < 22.1.4 February 8th Hot Fix >= 22.1.3, < 22.1.3 (semver) >= 22.1.2, < 22.1.2 (semver) >= 22.1.1, < 22.1.1 (semver) >= 21.2.3, < 21.2.3 (semver) >= 21.2.2, < 21.2.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | CVE Modified | CISA-ADP |
| Jun 19, 2025 | New CVE Received | [email protected] |
Volerion