
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23172 is a Server-Side Request Forgery (SSRF) vulnerability in the Versa Director SD-WAN orchestration platform that allows an authenticated attacker to send crafted HTTP requests to localhost, potentially leading to privilege escalation or remote code execution. The vulnerability resides in the "Add Webhook" and "Test Webhook" functionalities, which can be abused to execute commands on behalf of the versa user — an account with sudo privileges. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4. It was published on June 18–19, 2025, with the CVE assigned via HackerOne. The CVSS v3.1 base score is 7.2 (High) (Versa Security Portal, EUVD).
The root cause is classified as CWE-918 (Server-Side Request Forgery), mapped to CAPEC-664. The Webhook feature in Versa Director is designed to send HTTP notifications to external endpoints, but insufficient validation of the target URL allows an authenticated user to redirect requests to localhost (127.0.0.1) or internal network addresses. By crafting malicious webhook URLs, an attacker can interact with internal services running on the Director host. Because the versa user — under whose context these requests execute — holds sudo privileges, this SSRF can be chained to achieve privilege escalation or remote code execution. A proof-of-concept has been disclosed by third-party security researchers (Versa Security Portal, SecurityOnline).
Successful exploitation allows an authenticated attacker to interact with internal services on the Versa Director host via SSRF, and — by leveraging the versa user's sudo privileges — escalate to root-level access or execute arbitrary commands on the system. This can result in full confidentiality, integrity, and availability compromise of the Director node, which serves as the central SD-WAN orchestration platform. Compromise of the Director could enable an attacker to manipulate SD-WAN network configurations, intercept traffic policies, or pivot to managed network devices across the enterprise (Versa Security Portal, GBHackers).
A proof-of-concept for CVE-2025-23172 has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the disclosure date. Exploitation requires high privileges (an authenticated account on the Director platform), which limits the attack surface but does not eliminate risk from insider threats or compromised credentials. The EPSS score is approximately 0.29%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Versa Security Portal, EUVD).
localhost or 127.0.0.1 with a path corresponding to an internal service or API endpoint (e.g., http://127.0.0.1:<port>/api/command).versa user.versa user's sudo privileges, the attacker executes arbitrary commands with elevated permissions, potentially achieving root-level code execution on the Director host (Versa Security Portal, SecurityOnline).127.0.0.1 or localhost on unusual ports, originating from the Director web application process; unexpected internal service connections logged on the Director host.localhost, 127.0.0.1, or RFC-1918 addresses as the target URL; repeated or anomalous webhook trigger events from a single user account.versa user with elevated privileges (e.g., shell commands, script interpreters); sudo command executions by the versa user that are inconsistent with normal operations.versa user, particularly web shells or scripts in web-accessible paths (relevant if chained with CVE-2025-23171) (SecurityOnline, GBHackers).Versa Networks recommends upgrading Versa Director to a remediated software version as the only effective fix; there are no GUI-based workarounds to disable the vulnerable webhook functionality. Patched releases include versions beyond 22.1.4 — customers should consult the Versa support portal for the specific remediated build for their release branch (21.2.x and 22.1.x). As an interim measure, organizations should restrict access to the Versa Director management interface to trusted IP ranges and enforce the principle of least privilege for Director user accounts (Versa Security Portal, Versa Release 22-1-4).
Security news outlets including GBHackers, CyberPress, SecurityOnline, and ITSecurityNews covered the vulnerability shortly after disclosure, highlighting the risk of arbitrary command execution in SD-WAN infrastructure. Social media activity on Bluesky noted the dual disclosure alongside the related CVE-2025-23171 (webshell upload vulnerability), with researchers pointing out the compounded risk of chaining both flaws. Community sentiment reflects concern over the critical role Versa Director plays in enterprise SD-WAN management and the potential for supply-chain-style impact if the platform is compromised (GBHackers, SecurityOnline, CyberPress).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."