CVE-2024-39717
HIGH CISA KEVDescription
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| versa-networks | versa_director |
| versa-networks | versa_director |
| versa-networks | versa_director |
| versa-networks | versa_director |
| versa-networks | versa_director |
References
Frequently Asked Questions
What is CVE-2024-39717? +
How severe is CVE-2024-39717? +
What products are affected by CVE-2024-39717? +
How do I check if I'm vulnerable to CVE-2024-39717? +
Related Vulnerabilities
pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a …
The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectively as any …
Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload …
Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write …
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading …
Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php …