Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Versa Networks

First CVE: May 26, 2021Active for: 5 yearsTotal CVEs: 24

Versa Networks maintains a focused portfolio of software-defined wide-area networking (SD-WAN) and orchestration products, including its Versa Director controller, Versa Operating System, analytics platform, and Concerto management suite, which serve as the control and visibility layer for enterprise network edge deployments. The vendor's vulnerability disclosures remain concentrated in this narrowly scoped infrastructure role, with observed exposures spanning authentication, configuration, and API-level weaknesses typical of network management and orchestration platforms. Defenders tracking this vendor should prioritize control-plane access restrictions and credential management; live severity, exploitation, and exposure details are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
16.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Versa Networks over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 26, 2021
5 years ago
Most Recent CVE
Jun 19, 2025
400 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-34026HIGH
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative
May 21, 20257.596YESYES
CVE-2024-39717HIGH
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or P
Aug 22, 20247.265YESNO
CVE-2019-25029CRITICAL
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command inject
May 26, 20219.830NONO
CVE-2018-16495HIGH
In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Fai
May 26, 20218.827NONO
CVE-2018-16494HIGH
In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read
May 26, 20218.827NONO
CVE-2025-23168HIGH
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrus
Jun 19, 20258.824NONO
CVE-2018-16497HIGH
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a pote
May 26, 20217.824NONO
CVE-2021-39285MEDIUM
A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack.
Sep 7, 20216.121NONO
CVE-2019-25030MEDIUM
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algo
May 26, 20215.520NONO
CVE-2018-16499MEDIUM
In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unappro
May 26, 20215.920NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
50%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (25.0%)
Network9 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High1 (8.3%)
Unknown0 (0.0%)
User Interaction
None11 (91.7%)
Unknown0 (0.0%)
Required1 (8.3%)
Privileges Required
Low6 (50.0%)
High1 (8.3%)
None5 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
2 CVEs
16.7% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Versa Networks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Versa Networks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Versa Networks's Products

View all 3 CNAs →

Top CWEs