Versa Networks maintains a focused portfolio of software-defined wide-area networking (SD-WAN) and orchestration products, including its Versa Director controller, Versa Operating System, analytics platform, and Concerto management suite, which serve as the control and visibility layer for enterprise network edge deployments. The vendor's vulnerability disclosures remain concentrated in this narrowly scoped infrastructure role, with observed exposures spanning authentication, configuration, and API-level weaknesses typical of network management and orchestration platforms. Defenders tracking this vendor should prioritize control-plane access restrictions and credential management; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Versa Networks over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-34026HIGH The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative | May 21, 2025 | 7.5 | 96 | YES | YES |
CVE-2024-39717HIGH The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or P | Aug 22, 2024 | 7.2 | 65 | YES | NO |
CVE-2019-25029CRITICAL In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command inject | May 26, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-16495HIGH In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Fai | May 26, 2021 | 8.8 | 27 | NO | NO |
CVE-2018-16494HIGH In VOS and overly permissive "umask" may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read | May 26, 2021 | 8.8 | 27 | NO | NO |
CVE-2025-23168HIGH The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrus | Jun 19, 2025 | 8.8 | 24 | NO | NO |
CVE-2018-16497HIGH In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a pote | May 26, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-39285MEDIUM A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration web interface URL to create a XSS based attack. | Sep 7, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-25030MEDIUM In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algo | May 26, 2021 | 5.5 | 20 | NO | NO |
CVE-2018-16499MEDIUM In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unappro | May 26, 2021 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Versa Networks.
Media articles that mention a CVE ID that affects a product developed by Versa Networks — matched by CVE ID, not by vendor name.