The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting Versa Director to its Known Exploited Vulnerabilities (KEV) catalog following evidence of its active exploitation.
The medium-severity vulnerability, identified as CVE-2024-39717 and assigned a CVSS score of 6.6, relates to a file upload bug in the "Change Favicon" feature. This flaw allows a threat actor to upload a malicious file disguised as a seemingly harmless PNG image file.
"The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface," CISA stated in an advisory.
The advisory further explained that the "Change Favicon" feature enables the upload of a .png file, which can be exploited to upload a malicious file with a .PNG extension that is disguised as an image. Successful exploitation, however, requires the attacker to have authenticated access using Provider-Data-Center-Admin or Provider-Data-Center-System-Admin credentials.
Although specific details regarding the exploitation of CVE-2024-39717 remain unclear, a description in the NIST National Vulnerability Database (NVD) reveals that Versa Networks is aware of at least one confirmed instance where a customer was targeted. The description notes, "The Firewall guidelines which were published in 2015 and 2017 were not implemented by that customer. This non-implementation resulted in the bad actor being able to exploit this vulnerability without using the GUI."
Federal Civilian Executive Branch (FCEB) agencies are required to safeguard against this vulnerability by applying the vendor-provided fixes by September 13, 2024.
This announcement follows CISA's recent addition of four other security vulnerabilities from 2021 and 2022 to its KEV catalog:
- CVE-2021-33044 (CVSS score: 9.8) - Dahua IP Camera Authentication Bypass Vulnerability
- CVE-2021-33045 (CVSS score: 9.8) - Dahua IP Camera Authentication Bypass Vulnerability
- CVE-2021-31196 (CVSS score: 7.2) - Microsoft Exchange Server Information Disclosure Vulnerability
- CVE-2022-0185 (CVSS score: 8.4) - Linux Kernel Heap-Based Buffer Overflow Vulnerability
It is important to note that the China-linked threat actor known as UNC5174 (also referred to as Uteus or Uetus) was linked to the exploitation of CVE-2022-0185 by Mandiant earlier in March.
CVE-2021-31196, part of a broader set of vulnerabilities affecting Microsoft Exchange Server—collectively known as ProxyLogon, ProxyShell, ProxyToken, and ProxyOracle—has been observed in active exploitation campaigns. "CVE-2021-31196 has been observed in active exploitation campaigns, where threat actors target unpatched Microsoft Exchange Server instances," OP Innovate stated. "These attacks typically aim to gain unauthorized access to sensitive information, escalate privileges, or deploy further payloads such as ransomware or malware."