TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-34026

HIGHCISA KEV
7.5

Description

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

Details CVE

Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie5/21/2025
Derniere modification1/23/2026
Sourcekev
Observations honeypot0

CISA KEV

FournisseurVersa
ProduitConcerto
Nom vulnerabiliteVersa Concerto Improper Authentication Vulnerability
Date ajout KEV2026-01-22
Date limite remediation2026-02-12
Utilise dans ransomwareUnknown

Produits affectes

versa-networks:concerto

Faiblesses (CWE)

CWE-288

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.