Skip to content
COOEY

EXPOSURES › CVE-2024-39717

CVE-2024-39717

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-08-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-39717 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatchedsupply-chain

Versa Director allows unauthenticated upload of malicious PNG files via the 'Change Favicon' feature, enabling remote code execution for administrators.

The Versa Director GUI permits administrators to upload arbitrary files through the 'Change Favicon' feature, bypassing file type restrictions to execute malicious code. This vulnerability is actively exploited in the wild and poses a significant risk to DIB organizations relying on Versa Director for FedRAMP compliance, as it enables remote code execution without requiring a zero-day patch.

Shame score — The vulnerability allows remote code execution through a seemingly benign UI feature, and the vendor failed to patch it before it was actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.