CVE-2025-23173
Versa Director vulnerability analysis and mitigation

Overview

CVE-2025-23173 is a vulnerability in the Versa Director SD-WAN orchestration platform stemming from the default internet-exposed websockify service on TCP port 6080, which provides web-based access to uCPE virtual machines. The exposure of this service introduces significant risk due to known weaknesses in websockify that can potentially lead to remote code execution. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4. The vulnerability was published on June 18–19, 2025, with a CVSS v3.1 base score of 7.5 (High) (Versa Security Portal, Red Hat CVE).

Technical details

The root cause is an insecure default configuration (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) where the websockify service is bound to TCP port 6080 and exposed to the internet without adequate access controls. Websockify acts as a WebSocket-to-TCP proxy, and its known weaknesses can be leveraged by unauthenticated remote attackers to interact with uCPE virtual machine consoles managed by the Versa Director GUI. No authentication or network restriction is enforced by default, meaning any internet-accessible Versa Director instance is potentially reachable on this port. A proof-of-concept has been disclosed by third-party security researchers (Versa Security Portal, Red Hat CVE).

Impact

Successful exploitation could allow an unauthenticated remote attacker to interact with uCPE virtual machine consoles via the exposed websockify service, potentially leading to remote code execution on managed virtual machines. The primary impact is on integrity (CVSS integrity impact: High), with no direct confidentiality or availability impact scored, though RCE on network infrastructure components could enable further lateral movement within SD-WAN environments. Given that Versa Director is a central SD-WAN orchestration platform, compromise could have cascading effects on managed network infrastructure (Versa Security Portal, Red Hat CVE).

Exploitability

A proof-of-concept for this vulnerability has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the disclosure date. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it accessible to a wide range of threat actors. The EPSS score is approximately 0.098% (0.000980), indicating a currently low but non-negligible probability of exploitation in the near term. There is no current indication of CISA KEV catalog inclusion or known threat actor attribution (Versa Security Portal, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Use internet scanning tools such as Shodan or Censys to identify Versa Director instances with TCP port 6080 open and accessible from the internet.
  2. Confirm websockify exposure: Attempt a WebSocket connection to ws://<target>:6080/ to confirm the websockify service is running and unauthenticated.
  3. Identify target uCPE VMs: Interact with the websockify endpoint to enumerate available uCPE virtual machine console sessions exposed through the Versa Director GUI.
  4. Exploit websockify weaknesses: Leverage known websockify vulnerabilities (e.g., unauthorized proxy access or protocol-level weaknesses) to gain console access to uCPE virtual machines without authentication.
  5. Achieve code execution: Use the uCPE VM console access to execute arbitrary commands on the virtual machine, potentially enabling further lateral movement within the SD-WAN environment (Versa Security Portal).

Indicators of compromise

  • Network: Unexpected or anomalous inbound connections to TCP port 6080 on Versa Director hosts from external/internet IP addresses; WebSocket upgrade requests (Upgrade: websocket) to port 6080 from untrusted sources.
  • Logs: Versa Director access logs showing connections to the websockify service from unauthorized IP ranges; unusual uCPE console session initiations not correlated with legitimate administrator activity.
  • Process: Unexpected processes spawned within uCPE virtual machines that are not associated with normal administrative operations; unusual outbound network connections from uCPE VMs to external hosts.

Mitigation and workarounds

Versa Networks recommends upgrading Versa Director to a remediated software version; patched releases include 22.1.2, 22.1.3, and 22.1.4 (and their respective release notes are available via the Versa support portal). As an immediate workaround, restrict access to TCP port 6080 using firewall rules if uCPE console access is not required, preventing internet-facing exposure of the websockify service. Organizations should audit their Versa Director deployments to confirm port 6080 is not publicly accessible and review network segmentation controls around the Director management plane (Versa Security Portal, Release 22.1.4).

Community reactions

Versa Networks issued an official security bulletin acknowledging the vulnerability and noting that a proof-of-concept had been disclosed by third-party security researchers, while stating no confirmed exploitation had been observed. The vulnerability was also tracked by ENISA's European Vulnerability Database (EUVD-2025-18672) and referenced by Red Hat's CVE tracking, indicating broad industry awareness. No significant independent researcher commentary or notable social media discussion has been identified beyond the initial disclosure (Versa Security Portal, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Versa Director vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24288CRITICAL9.8
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoYesJun 19, 2025
CVE-2025-23173HIGH7.5
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23172HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23171HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-24291MEDIUM6.1
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management