Vulnerability record · CVE-2024-39717 · published 22 August 2024
CVE-2024-39717: Versa Director GUI unrestricted file upload via favicon option
Versa Networks · Versa Director
Versa Director's GUI lets a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin customize the interface, including the "Change Favicon" option. That option fails to properly restrict uploaded file types, so a file ending in .png can be uploaded and used to masquerade as an image while actually being malicious. Because the flaw is an unrestricted upload (CWE-434) in an administrative interface, it matters as a potential path to code execution or system compromise on the Director appliance.
Description
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a high-severity unrestricted upload in an administrative interface and is listed in CISA KEV as exploited in the wild, though it requires prior privileged authentication.
What it is
Versa Director's GUI lets a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin customize the interface, including the "Change Favicon" option. That option fails to properly restrict uploaded file types, so a file ending in .png can be uploaded and used to masquerade as an image while actually being malicious. Because the flaw is an unrestricted upload (CWE-434) in an administrative interface, it matters as a potential path to code execution or system compromise on the Director appliance.
Impact
An attacker who already holds a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin account can upload a malicious file disguised as a .png, potentially gaining code execution or otherwise compromising the Versa Director system.
Attack surface
The flaw is reached over the network through the Versa Director GUI's favicon customization feature. It requires a valid authenticated session with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges; tenant-level users cannot reach it, and no user interaction beyond the upload is described.
Exploitation
CVE-2024-39717 was added to CISA KEV on 2024-08-23 with a remediation due date of 2024-09-13, indicating known exploitation in the wild. EPSS gives a 30-day probability of about 4.0% (90th percentile), and the vendor advisory and KEV listing are the only references provided.
What to do
- Apply the vendor's patched Versa Director release or the mitigations in the Versa security bulletin as soon as possible.
- If patching is not immediately possible, restrict or disable the favicon customization feature and follow CISA KEV guidance, including discontinuing use if no mitigation exists.
- Limit Provider-Data-Center-Admin and Provider-Data-Center-System-Admin accounts to the minimum necessary personnel and enforce strong authentication.
- Monitor and audit administrative accounts for unexpected creation or privilege changes that could enable this upload.
- Review uploaded favicon files for content that does not match a valid image format.
Detection
- Monitor Versa Director logs for favicon upload events and inspect uploaded files for non-image content or embedded code.
- Alert on administrative account activity outside normal change windows, especially uploads to the GUI customization feature.
- Hunt for suspicious files with .png extensions in Director web directories that fail image parsing or contain executable content.
- Correlate Director administrative logins with subsequent process execution or outbound connections from the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-39717 to the Known Exploited Vulnerabilities catalog on 23 August 2024 as "Versa Director Dangerous File Type Upload Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-39717 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-39717), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.