
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23173 is a vulnerability in the Versa Director SD-WAN orchestration platform stemming from the default internet-exposed websockify service on TCP port 6080, which provides web-based access to uCPE virtual machines. The exposure of this service introduces significant risk due to known weaknesses in websockify that can potentially lead to remote code execution. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4. The vulnerability was published on June 18–19, 2025, with a CVSS v3.1 base score of 7.5 (High) (Versa Security Portal, Red Hat CVE).
The root cause is an insecure default configuration (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor) where the websockify service is bound to TCP port 6080 and exposed to the internet without adequate access controls. Websockify acts as a WebSocket-to-TCP proxy, and its known weaknesses can be leveraged by unauthenticated remote attackers to interact with uCPE virtual machine consoles managed by the Versa Director GUI. No authentication or network restriction is enforced by default, meaning any internet-accessible Versa Director instance is potentially reachable on this port. A proof-of-concept has been disclosed by third-party security researchers (Versa Security Portal, Red Hat CVE).
Successful exploitation could allow an unauthenticated remote attacker to interact with uCPE virtual machine consoles via the exposed websockify service, potentially leading to remote code execution on managed virtual machines. The primary impact is on integrity (CVSS integrity impact: High), with no direct confidentiality or availability impact scored, though RCE on network infrastructure components could enable further lateral movement within SD-WAN environments. Given that Versa Director is a central SD-WAN orchestration platform, compromise could have cascading effects on managed network infrastructure (Versa Security Portal, Red Hat CVE).
A proof-of-concept for this vulnerability has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the disclosure date. The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it accessible to a wide range of threat actors. The EPSS score is approximately 0.098% (0.000980), indicating a currently low but non-negligible probability of exploitation in the near term. There is no current indication of CISA KEV catalog inclusion or known threat actor attribution (Versa Security Portal, Red Hat CVE).
ws://<target>:6080/ to confirm the websockify service is running and unauthenticated.Upgrade: websocket) to port 6080 from untrusted sources.Versa Networks recommends upgrading Versa Director to a remediated software version; patched releases include 22.1.2, 22.1.3, and 22.1.4 (and their respective release notes are available via the Versa support portal). As an immediate workaround, restrict access to TCP port 6080 using firewall rules if uCPE console access is not required, preventing internet-facing exposure of the websockify service. Organizations should audit their Versa Director deployments to confirm port 6080 is not publicly accessible and review network segmentation controls around the Director management plane (Versa Security Portal, Release 22.1.4).
Versa Networks issued an official security bulletin acknowledging the vulnerability and noting that a proof-of-concept had been disclosed by third-party security researchers, while stating no confirmed exploitation had been observed. The vulnerability was also tracked by ENISA's European Vulnerability Database (EUVD-2025-18672) and referenced by Red Hat's CVE tracking, indicating broad industry awareness. No significant independent researcher commentary or notable social media discussion has been identified beyond the initial disclosure (Versa Security Portal, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."