CNNVD-202506-2527 Information

CNNVD ID

CNNVD-202506-2527

CVE-2025-23172

  • CNNVD Published: 2025-06-18

Description (Chinese)

Versa Director是美国Versa公司的一个虚拟化和服务创建平台。可简化使用Versa FlexVNF的服务创建,自动化和交付。 Versa Director存在安全漏洞,该漏洞源于Webhook功能滥用,可能导致权限提升或远程代码执行。

Description (English)

Versa Director is a virtualization and service creation platform for Versa in the United States. Services created, automated and delivered using Versa FlexVNF could be streamlined. Versa Director has a security loophole, which stems from the misuse of the Webhook function, which may lead to power enhancement or remote code enforcement.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Versa

Published

2025-06-18

Last Modified

2026-02-24

References

https://support.versa-networks.com/support/solutions/articles/23000026033-release-22-1-3 https://security-portal.versa-networks.com/emailbulletins/68526e7bdc94d6b9f2faf71b https://support.versa-networks.com/support/solutions/articles/23000024323-release-21-2-3 https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4 https://support.versa-networks.com/support/solutions/articles/23000025680-release-22-1-2 https://nvd.nist.gov/vuln/detail/CVE-2025-23172

Patch

https://support.versa-networks.com/support/solutions/articles/23000026308-versa-director-installation

Share on: