Versa Networks addresses critical vulnerability in Versa Director (CVSS 10)

ISGroup Cybersecurity

This vulnerability has received the maximum CVSS score of 10, highlighting its critical severity. It is an unauthenticated access vulnerability, which significantly increases the risk of exploitation. Versa Director, being a high-value target, has already been exploited in the past by malicious actors.

ProductVersa Director
Date2024-11-25 16:31:23
Information
  • Trending
  • Fix Available

Technical Summary

Versa Director uses PostgreSQL (Postgres) to store operational and configuration data and to enable High Availability (HA) features. However, the default configuration of Versa Director includes a shared password across all instances and configures Postgres to listen on all network interfaces.

This creates a severe vulnerability where an unauthenticated attacker could:

  • Access and administer the database;
  • Read the contents of the local filesystem;
  • Escalate privileges on the system.

Recommendations

Starting with the latest version 22.1.4 of Versa Director, the software will automatically restrict access to Postgres and HA ports only to local and peer Versa Directors. For older versions, Versa recommends performing manual hardening of the HA ports. Please refer to the following link for the steps to follow: SecureHAPorts.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert