Service Exposure and Default Credentials in Versa Director Software by Versa Networks
CVE-2025-24288

9.8CRITICAL

Key Information:

Vendor

Versa

Status
Vendor
CVE Published:
19 June 2025

What is CVE-2025-24288?

The Versa Director software by Versa Networks has been found to expose multiple services by default, which may grant attackers an easier entry point into the system. This vulnerability arises from the use of default credentials across various accounts that often have elevated privileges, including sudo access. Critical services such as SSH and PostgreSQL are accessible from the internet by default, increasing the potential for unauthorized access. Although no direct exploitation of this vulnerability has been reported, research teams have disclosed proof of concept methods. To mitigate this vulnerability, Versa Networks advises users to implement strong password policies, routinely review authentication logs, and ensure regular password updates to bolster security.

Affected Version(s)

Director 21.2.2

Director 21.2.3

Director 22.1.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-24288 : Service Exposure and Default Credentials in Versa Director Software by Versa Networks