Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-39717

Опубликовано: 22 авг. 2024
Источник: nvd
CVSS3: 6.6
CVSS3: 7.2
EPSS Низкий

Описание

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:versa-networks:versa_director:21.2.2:*:*:*:*:*:*:*
cpe:2.3:a:versa-networks:versa_director:21.2.3:*:*:*:*:*:*:*
cpe:2.3:a:versa-networks:versa_director:22.1.1:*:*:*:*:*:*:*
cpe:2.3:a:versa-networks:versa_director:22.1.2:*:*:*:*:*:*:*
cpe:2.3:a:versa-networks:versa_director:22.1.3:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04642
Низкий

6.6 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 6.6
github
больше 1 года назад

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in. Severity: HIGH Exploitation Status: Versa Networks is aware of one confirmed customer reported instance where this vulnerability was exploited because the Firewall guidelines which were published in 2015 & 2017 were not implemented by that customer. This non-implementation resulted in the bad actor being able to exploit this vulnerability without using the GUI. In our testing (not exhaustive, as not all numerical versions of maj...

CVSS3: 7.2
fstec
больше 1 года назад

Уязвимость функции загрузки файлов в интерфейсе «Change Favicon программной платформы управления сетевой инфраструктуры Versa Director, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 89%
0.04642
Низкий

6.6 Medium

CVSS3

7.2 High

CVSS3

Дефекты

CWE-434
CWE-434