← Vulnerability feed

Vulnerability record · CVE-2024-39717 · published 22 August 2024

CVE-2024-39717: Versa Director GUI unrestricted file upload via favicon option

Versa Networks · Versa Director

Versa Director's GUI lets a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin customize the interface, including the "Change Favicon" option. That option fails to properly restrict uploaded file types, so a file ending in .png can be uploaded and used to masquerade as an image while actually being malicious. Because the flaw is an unrestricted upload (CWE-434) in an administrative interface, it matters as a potential path to code execution or system compromise on the Director appliance.

7.2 CVSS 3.1 High CISA KEV since 23 Aug 2024 EPSS 4.0% · top 9.8% CWE-434 · Unrestricted file upload
7.2CVSS 3.1 base score
4.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is a high-severity unrestricted upload in an administrative interface and is listed in CISA KEV as exploited in the wild, though it requires prior privileged authentication.

What it is

Versa Director's GUI lets a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin customize the interface, including the "Change Favicon" option. That option fails to properly restrict uploaded file types, so a file ending in .png can be uploaded and used to masquerade as an image while actually being malicious. Because the flaw is an unrestricted upload (CWE-434) in an administrative interface, it matters as a potential path to code execution or system compromise on the Director appliance.

Impact

An attacker who already holds a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin account can upload a malicious file disguised as a .png, potentially gaining code execution or otherwise compromising the Versa Director system.

Attack surface

The flaw is reached over the network through the Versa Director GUI's favicon customization feature. It requires a valid authenticated session with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges; tenant-level users cannot reach it, and no user interaction beyond the upload is described.

Exploitation

CVE-2024-39717 was added to CISA KEV on 2024-08-23 with a remediation due date of 2024-09-13, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 4.0% (90th percentile), and the vendor advisory and KEV listing are the only references provided.

What to do

  • Apply the vendor's patched Versa Director release or the mitigations in the Versa security bulletin as soon as possible.
  • If patching is not immediately possible, restrict or disable the favicon customization feature and follow CISA KEV guidance, including discontinuing use if no mitigation exists.
  • Limit Provider-Data-Center-Admin and Provider-Data-Center-System-Admin accounts to the minimum necessary personnel and enforce strong authentication.
  • Monitor and audit administrative accounts for unexpected creation or privilege changes that could enable this upload.
  • Review uploaded favicon files for content that does not match a valid image format.

Detection

  • Monitor Versa Director logs for favicon upload events and inspect uploaded files for non-image content or embedded code.
  • Alert on administrative account activity outside normal change windows, especially uploads to the GUI customization feature.
  • Hunt for suspicious files with .png extensions in Director web directories that fail image parsing or contain executable content.
  • Correlate Director administrative logins with subsequent process execution or outbound connections from the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-39717 to the Known Exploited Vulnerabilities catalog on 23 August 2024 as "Versa Director Dangerous File Type Upload Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 September 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-39717 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-42450Versa-networks versa director hard-coded credentials vulnerabilityThe Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Ve…EPSS 0.58%9.8CVE-2025-24288Versa-networks versa director insecure default initialization vulnerabilityThe Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple acco…EPSS 0.47%9.8CVE-2019-25029Versa-networks versa director command injection vulnerabilityIn Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnera…EPSS 2.4%8.8CVE-2025-23168Versa-networks versa director authentication bypass by spoofing vulnerabilityThe Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS…EPSS 0.40%7.5CVE-2025-23173Versa-networks versa director information exposure vulnerabilityThe Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the …EPSS 0.62%7.2CVE-2025-23171Versa-networks versa director unrestricted file upload vulnerabilityThe Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit fil…EPSS 0.55%7.2CVE-2025-23172Versa-networks versa director server-side request forgery (ssrf) vulnerabilityThe Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add W…EPSS 1.1%6.7CVE-2025-23170Versa-networks versa director command injection vulnerabilityThe Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2024-39717), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.