
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23170 is a command injection vulnerability in the Versa Director SD-WAN orchestration platform, specifically in the shell-connect.py Python script used to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. An attacker with high-privileged local access can inject arbitrary commands through the user argument of this script. The vulnerability was published on June 18–19, 2025, and assigned a CVSS v3.1 base score of 6.7 (High) (Versa Security Portal, Red Hat CVE). Affected products include Versa Director versions up to and including 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4.
The root cause is improper neutralization of special elements in a command (CWE-77 — Command Injection). The vulnerable component is shell-connect.py, a Python script invoked by the Shell-In-A-Box web-based terminal interface within Versa Director to establish SSH sessions. The user argument passed to this script is not properly sanitized, allowing an attacker to inject shell metacharacters or command delimiters that are subsequently executed by the underlying operating system. Exploitation requires local access and high privileges (e.g., an authenticated administrative session), limiting the attack surface but not eliminating risk in environments where privileged accounts may be compromised (Versa Security Portal, Red Hat CVE). A proof-of-concept has been disclosed by third-party security researchers.
Successful exploitation grants an attacker the ability to execute arbitrary commands on the Versa Director host system, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive configuration data, modify system files, disrupt SD-WAN orchestration services, or use the Director as a pivot point to reach managed CPE devices across the network. Given that Versa Director is a central orchestration platform for SD-WAN infrastructure, compromise could have cascading effects on all managed network devices (Versa Security Portal, Red Hat CVE).
A proof-of-concept for CVE-2025-23170 has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the disclosure date (Versa Security Portal). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the near term. Exploitation requires high privileges and local access, which constrains opportunistic exploitation but remains a concern for insider threats or post-compromise scenarios.
user argument passed to the shell-connect.py Python script when initiating an SSH session.user argument containing shell metacharacters or command delimiters (e.g., ; id, $(whoami), or a reverse shell payload) to break out of the intended command context.;, $(), |, &&) in the user field; OS-level audit logs (e.g., auditd) showing unexpected command execution spawned from the shell-connect.py process.shell-connect.py, such as /bin/bash, curl, wget, nc, or other network utilities not typical of normal SSH session initiation.Versa Networks recommends upgrading Versa Director to a remediated software version as the primary mitigation, as there are no available workarounds to disable the vulnerable GUI option (Versa Security Portal). Patched releases include versions 22.1.2, 22.1.3, and 22.1.4 (and later), as well as 21.2.3 for the 21.x branch. Organizations should also enforce the principle of least privilege for Director administrative accounts, restrict access to the Director management interface to trusted networks, and monitor Shell-In-A-Box usage for anomalous activity.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."