Service Exposure and Default Credentials in Versa Director Software by Versa Networks
CVE-2025-24288

Currently unrated

Key Information:

Vendor
CVE Published:
19 June 2025

What is CVE-2025-24288?

The Versa Director software by Versa Networks has been found to expose multiple services by default, which may grant attackers an easier entry point into the system. This vulnerability arises from the use of default credentials across various accounts that often have elevated privileges, including sudo access. Critical services such as SSH and PostgreSQL are accessible from the internet by default, increasing the potential for unauthorized access. Although no direct exploitation of this vulnerability has been reported, research teams have disclosed proof of concept methods. To mitigate this vulnerability, Versa Networks advises users to implement strong password policies, routinely review authentication logs, and ensure regular password updates to bolster security.

References

Timeline

  • Vulnerability published

.
CVE-2025-24288 : Service Exposure and Default Credentials in Versa Director Software by Versa Networks