CVE-2025-24288
Last modified
CVE-2025-24288 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other services. Versa Networks is not aware of any reported instance where this vulnerability was exploited. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other services. Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. Workarounds or Mitigation: Versa recommends the following security controls: 1) Change default passwords to complex passwords 2) Passwords must be complex with at least 8 characters that comprise of upper case, and lower case alphabets, as well as at at least one digit, and one special character 3) Passwords must be changed at least every 90 days 4) Password change history is checked to ensure that the at least the last 5 passwords must be used when changing password. 5) Review and audit logs for all authentication attempts to check for unauthorized/suspicious login attempts and enforce remediation steps.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-24288?
How severe is CVE-2025-24288?
How do I fix CVE-2025-24288?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24282A library injection issue was addressed with additional rest…5.5
- CVE-2025-24283A logging issue was addressed with improved data redaction. …5.5
- CVE-2025-24284This issue was addressed with improved checks to prevent una…8.8
- CVE-2025-24285Multiple Improper Input Validation vulnerabilities in UniFi …9.8
- CVE-2025-24286A vulnerability allowing an authenticated user with the Back…4.9
- CVE-2025-24287A vulnerability allowing local system users to modify direct…6.1
- CVE-2025-24289A Cross-Site Request Forgery (CSRF) leading to Cross-Site Sc…7.5
- CVE-2025-24290Multiple Authenticated SQL Injection vulnerabilities found i…9.9
- CVE-2025-24291The Versa Director SD-WAN orchestration platform provides fu…6.1
- CVE-2025-24292A misconfigured query in UniFi Network (v9.1.120 and earlier…6.8
- CVE-2025-24293# Active Storage allowed transformation methods potentially …9.2
- CVE-2025-24294The attack vector is a potential Denial of Service (DoS). Th…7.5
Are you affected by CVE-2025-24288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
