← Back to CVE List
Vulnerability Analysis

CVE-2024-39717

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

CISA KEV
CVSS Base Score
6.6
MEDIUM
Exploitability:0.8
Impact Score:5.9
Temporal Score:-
EPSS:4.01%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2024-08-23
Ransomware Use
Unknown
KEV Due Date
2024-09-13
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
4.006%
EPSS Percentile
89.2th pct
GitHub Severity
MODERATE
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD