login
quiescence.eu
Naar inhoud

CVE-2025-34026

Versa Concerto Improper Authentication Vulnerability

7.5
CVSS
83.2%
EPSS (exploit prob.)
99.6%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2026-01-22
Added

Summary

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.

Affected software

Vendor: Versa  ·  Product: Concerto

Weakness types (CWE):

CWE-288

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in Versa

CVENameEPSSExploited
CVE-2024-39717 Versa Director Dangerous File Type Upload Vulnerability 4.0% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.