CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA code...Show more |
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenan...Show more |
1Versa Networks 1Versa Director Nov 21, 2024 Sep 7, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack. |
1Versa Networks 3Versa Analytics Versa DirectorVersa Operating SystemNov 21, 2024 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the Merkle-Damgardconstr...Show more |
1Versa Networks 1Versa Director Nov 21, 2024 May 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an applica...Show more |
1Versa Networks 1Versa Director Nov 21, 2024 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Tru...Show more |
1Versa Networks 1Versa Director Nov 21, 2024 May 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Versa Director, the un-authentication request found. |