CVE-2025-23170
Versa Director vulnerability analysis and mitigation

Overview

CVE-2025-23170 is a command injection vulnerability in the Versa Director SD-WAN orchestration platform, specifically in the shell-connect.py Python script used to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. An attacker with high-privileged local access can inject arbitrary commands through the user argument of this script. The vulnerability was published on June 18–19, 2025, and assigned a CVSS v3.1 base score of 6.7 (High) (Versa Security Portal, Red Hat CVE). Affected products include Versa Director versions up to and including 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4.

Technical details

The root cause is improper neutralization of special elements in a command (CWE-77 — Command Injection). The vulnerable component is shell-connect.py, a Python script invoked by the Shell-In-A-Box web-based terminal interface within Versa Director to establish SSH sessions. The user argument passed to this script is not properly sanitized, allowing an attacker to inject shell metacharacters or command delimiters that are subsequently executed by the underlying operating system. Exploitation requires local access and high privileges (e.g., an authenticated administrative session), limiting the attack surface but not eliminating risk in environments where privileged accounts may be compromised (Versa Security Portal, Red Hat CVE). A proof-of-concept has been disclosed by third-party security researchers.

Impact

Successful exploitation grants an attacker the ability to execute arbitrary commands on the Versa Director host system, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive configuration data, modify system files, disrupt SD-WAN orchestration services, or use the Director as a pivot point to reach managed CPE devices across the network. Given that Versa Director is a central orchestration platform for SD-WAN infrastructure, compromise could have cascading effects on all managed network devices (Versa Security Portal, Red Hat CVE).

Exploitability

A proof-of-concept for CVE-2025-23170 has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the disclosure date (Versa Security Portal). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the near term. Exploitation requires high privileges and local access, which constrains opportunistic exploitation but remains a concern for insider threats or post-compromise scenarios.

Exploitation steps

  1. Gain privileged access: Obtain high-privileged (administrative) credentials to the Versa Director web interface, either through credential theft, phishing, or reuse of compromised accounts.
  2. Navigate to Shell-In-A-Box: Access the Shell-In-A-Box terminal feature within the Versa Director GUI, which is used to initiate SSH sessions to remote CPEs or the Director shell.
  3. Identify the vulnerable parameter: Locate the user argument passed to the shell-connect.py Python script when initiating an SSH session.
  4. Inject malicious payload: Supply a crafted value for the user argument containing shell metacharacters or command delimiters (e.g., ; id, $(whoami), or a reverse shell payload) to break out of the intended command context.
  5. Achieve arbitrary command execution: The injected commands are executed by the underlying OS in the context of the Versa Director process, enabling data exfiltration, persistence mechanisms, or lateral movement to managed CPE devices (Versa Security Portal).

Indicators of compromise

  • Logs: Unexpected or malformed entries in Versa Director access logs involving the Shell-In-A-Box interface with unusual characters (;, $(), |, &&) in the user field; OS-level audit logs (e.g., auditd) showing unexpected command execution spawned from the shell-connect.py process.
  • Process: Unusual child processes spawned by the Python interpreter running shell-connect.py, such as /bin/bash, curl, wget, nc, or other network utilities not typical of normal SSH session initiation.
  • Network: Unexpected outbound connections from the Versa Director host to external IP addresses, particularly on non-standard ports, following Shell-In-A-Box activity.
  • File System: New or modified files in the Versa Director installation directories, unexpected cron jobs, or new user accounts created on the Director host after Shell-In-A-Box usage.

Mitigation and workarounds

Versa Networks recommends upgrading Versa Director to a remediated software version as the primary mitigation, as there are no available workarounds to disable the vulnerable GUI option (Versa Security Portal). Patched releases include versions 22.1.2, 22.1.3, and 22.1.4 (and later), as well as 21.2.3 for the 21.x branch. Organizations should also enforce the principle of least privilege for Director administrative accounts, restrict access to the Director management interface to trusted networks, and monitor Shell-In-A-Box usage for anomalous activity.

Additional resources


SourceThis report was generated using AI

Related Versa Director vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24288CRITICAL9.8
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoYesJun 19, 2025
CVE-2025-23173HIGH7.5
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23172HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23171HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-24291MEDIUM6.1
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management