Based on proof of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Versa Director security issue to its list of known exploited vulnerabilities (KEVs).
A file upload problem affecting the “Change Favicon” feature is the source of the medium-severity vulnerability, identified as CVE-2024-39717 (CVSS score: 6.6). This exploit could enable a threat actor to submit a malicious file by disguising it as a seemingly innocent PNG image file.
According to a CISA alert, administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin access can alter the user interface of the Versa Director GUI through an unlimited upload of files with a hazardous type vulnerability read more about CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
