← Vulnerability feed

Vulnerability record · CVE-2024-42450 · published 19 November 2024

CVE-2024-42450: Versa-networks versa director hard-coded credentials vulnerability

Versa Networks · Versa Director

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all network interfaces. This combination allows an unauthenticated attacker to access and administer the database or read local filesystem contents to escalate privileges on the system. Exploitation Status: Versa Networks is not aware of this exploitation in any production systems. A proof of concept exists in the lab environment. Workarounds or Mitigation: Starting with the latest 22.1.4 version of Versa Director, the software will automatically restrict access to the Postgres and HA ports to only the local and peer Versa Directors. For older releases, Versa recommends performing manual hardening of HA ports. Please refer to the following link for the steps https://docs.versa-networks.com/Solutions/System_Hardening/Perform_Manual_Hardening_for_Versa_Director#Secure_HA_Ports This vulnerability is not exploitable on Versa Directors if published Firewall guidelines are implemented. We have validated that no Versa-hosted head ends have been affected by this vulnerability. All Versa-hosted head ends are patched and hardened. Please contact Versa Technical Support or Versa account team for any further assistance. Software Download Links: 22.1.4: https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4

10.0 CVSS 3.1 Critical EPSS 0.58% · top 54.2% CWE-798 · Hard-coded credentials
10.0CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
3 Sep 2026Last modified by NVD

Description

The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all network interfaces. This combination allows an unauthenticated attacker to access and administer the database or read local filesystem contents to escalate privileges on the system. Exploitation Status: Versa Networks is not aware of this exploitation in any production systems. A proof of concept exists in the lab environment. Workarounds or Mitigation: Starting with the latest 22.1.4 version of Versa Director, the software will automatically restrict access to the Postgres and HA ports to only the local and peer Versa Directors. For older releases, Versa recommends performing manual hardening of HA ports. Please refer to the following link for the steps https://docs.versa-networks.com/Solutions/System_Hardening/Perform_Manual_Hardening_for_Versa_Director#Secure_HA_Ports This vulnerability is not exploitable on Versa Directors if published Firewall guidelines are implemented. We have validated that no Versa-hosted head ends have been affected by this vulnerability. All Versa-hosted head ends are patched and hardened. Please contact Versa Technical Support or Versa account team for any further assistance. Software Download Links: 22.1.4: https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-42450 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2024-39717Versa Director GUI unrestricted file upload via favicon optionVersa Director's GUI lets a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin customize the interface, including the "Change Favicon" o…KEVEPSS 4.0%analysed9.8CVE-2025-24288Versa-networks versa director insecure default initialization vulnerabilityThe Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple acco…EPSS 0.47%9.8CVE-2019-25029Versa-networks versa director command injection vulnerabilityIn Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnera…EPSS 2.4%8.8CVE-2025-23168Versa-networks versa director authentication bypass by spoofing vulnerabilityThe Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS…EPSS 0.40%7.5CVE-2025-23173Versa-networks versa director information exposure vulnerabilityThe Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the …EPSS 0.62%7.2CVE-2025-23171Versa-networks versa director unrestricted file upload vulnerabilityThe Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit fil…EPSS 0.55%7.2CVE-2025-23172Versa-networks versa director server-side request forgery (ssrf) vulnerabilityThe Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add W…EPSS 1.1%6.7CVE-2025-23170Versa-networks versa director command injection vulnerabilityThe Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2024-42450), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.