CVE-2025-23172
Versa Director vulnerability analysis and mitigation

Overview

CVE-2025-23172 is a Server-Side Request Forgery (SSRF) vulnerability in the Versa Director SD-WAN orchestration platform that allows an authenticated attacker to send crafted HTTP requests to localhost, potentially leading to privilege escalation or remote code execution. The vulnerability resides in the "Add Webhook" and "Test Webhook" functionalities, which can be abused to execute commands on behalf of the versa user — an account with sudo privileges. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4. It was published on June 18–19, 2025, with the CVE assigned via HackerOne. The CVSS v3.1 base score is 7.2 (High) (Versa Security Portal, EUVD).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), mapped to CAPEC-664. The Webhook feature in Versa Director is designed to send HTTP notifications to external endpoints, but insufficient validation of the target URL allows an authenticated user to redirect requests to localhost (127.0.0.1) or internal network addresses. By crafting malicious webhook URLs, an attacker can interact with internal services running on the Director host. Because the versa user — under whose context these requests execute — holds sudo privileges, this SSRF can be chained to achieve privilege escalation or remote code execution. A proof-of-concept has been disclosed by third-party security researchers (Versa Security Portal, SecurityOnline).

Impact

Successful exploitation allows an authenticated attacker to interact with internal services on the Versa Director host via SSRF, and — by leveraging the versa user's sudo privileges — escalate to root-level access or execute arbitrary commands on the system. This can result in full confidentiality, integrity, and availability compromise of the Director node, which serves as the central SD-WAN orchestration platform. Compromise of the Director could enable an attacker to manipulate SD-WAN network configurations, intercept traffic policies, or pivot to managed network devices across the enterprise (Versa Security Portal, GBHackers).

Exploitability

A proof-of-concept for CVE-2025-23172 has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the disclosure date. Exploitation requires high privileges (an authenticated account on the Director platform), which limits the attack surface but does not eliminate risk from insider threats or compromised credentials. The EPSS score is approximately 0.29%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Versa Security Portal, EUVD).

Exploitation steps

  1. Reconnaissance: Identify an internet-facing or internally accessible Versa Director instance running a vulnerable version (21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, or 22.1.4). Obtain valid credentials for an authenticated user account on the platform.
  2. Access Webhook functionality: Log in to the Versa Director GUI and navigate to the "Add Webhook" or "Test Webhook" feature within the notification/alerting configuration section.
  3. Craft malicious webhook URL: Instead of specifying a legitimate external HTTP endpoint, supply a URL targeting localhost or 127.0.0.1 with a path corresponding to an internal service or API endpoint (e.g., http://127.0.0.1:<port>/api/command).
  4. Trigger the webhook: Use the "Test Webhook" function to send the crafted HTTP request. The Director platform forwards the request to the specified localhost address on behalf of the versa user.
  5. Achieve privilege escalation or RCE: By targeting internal services that accept commands or scripts, and leveraging the versa user's sudo privileges, the attacker executes arbitrary commands with elevated permissions, potentially achieving root-level code execution on the Director host (Versa Security Portal, SecurityOnline).

Indicators of compromise

  • Network: Outbound HTTP requests from the Versa Director host to 127.0.0.1 or localhost on unusual ports, originating from the Director web application process; unexpected internal service connections logged on the Director host.
  • Logs: Versa Director application logs showing webhook test or creation events with localhost, 127.0.0.1, or RFC-1918 addresses as the target URL; repeated or anomalous webhook trigger events from a single user account.
  • Process: Unexpected processes spawned by the versa user with elevated privileges (e.g., shell commands, script interpreters); sudo command executions by the versa user that are inconsistent with normal operations.
  • File System: New or modified files in directories writable by the versa user, particularly web shells or scripts in web-accessible paths (relevant if chained with CVE-2025-23171) (SecurityOnline, GBHackers).

Mitigation and workarounds

Versa Networks recommends upgrading Versa Director to a remediated software version as the only effective fix; there are no GUI-based workarounds to disable the vulnerable webhook functionality. Patched releases include versions beyond 22.1.4 — customers should consult the Versa support portal for the specific remediated build for their release branch (21.2.x and 22.1.x). As an interim measure, organizations should restrict access to the Versa Director management interface to trusted IP ranges and enforce the principle of least privilege for Director user accounts (Versa Security Portal, Versa Release 22-1-4).

Community reactions

Security news outlets including GBHackers, CyberPress, SecurityOnline, and ITSecurityNews covered the vulnerability shortly after disclosure, highlighting the risk of arbitrary command execution in SD-WAN infrastructure. Social media activity on Bluesky noted the dual disclosure alongside the related CVE-2025-23171 (webshell upload vulnerability), with researchers pointing out the compounded risk of chaining both flaws. Community sentiment reflects concern over the critical role Versa Director plays in enterprise SD-WAN management and the potential for supply-chain-style impact if the platform is compromised (GBHackers, SecurityOnline, CyberPress).

Additional resources


SourceThis report was generated using AI

Related Versa Director vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24288CRITICAL9.8
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoYesJun 19, 2025
CVE-2025-23173HIGH7.5
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23172HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23171HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-24291MEDIUM6.1
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management