boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-39717

Versa Director
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0401   90.2   YES
AFFECTED
  Product   Versions  Fixed
  Director  21.2.2 –  —
TIMELINE
  Jun 28  Reserved by hackerone
  Aug 22  Published (CNA: hackerone)
  Aug 23  Added to CISA KEV, remediation due 2024-09-13
CWE-434 · CNA: hackerone · CVSS v3.0 · 2 references · KEV due September 13, 2024

Description

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 28, 2024ReservedReserved by hackerone
August 22, 2024PublishedPublished (CNA: hackerone)
August 23, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-09-13

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
VersaDirector—21.2.2—

Weaknesses

CWE-434

References (2)

Related

Authoritative record: CVE-2024-39717 at cve.org

Vendors: versa

Weaknesses: CWE-434

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-39717 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.