The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
Incorrect Traefik reverse proxy configuration allows an attacker to bypass authentication mechanisms and gain direct access to internal administrative endpoints. In particular, the internal Actuator endpoint becomes accessible, which can expose sensitive operational data such as heap dumps and trace logs. Access to these resources does not require any credentials or user interaction.
A remote attacker without authentication can gain access to sensitive internal system data, including memory dumps and logs, which may lead to disclosure of configuration data, credentials, or other critical information stored in the platform's memory. It is also possible to leverage the obtained information for subsequent attacks on the infrastructure.
Apply patches available from the vendor immediately in accordance with references published on the Versa Networks security portal (security-portal.versa-networks.com). Until the fix is implemented, it is recommended to restrict network access to Concerto platform administrative endpoints using firewall or ACL rules, and monitor network traffic for unauthorized access attempts to Actuator endpoints.
Versa Concerto versions 12.1.2 through 12.2.0 inclusive. The vendor indicates that additional versions may also be vulnerable.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XVersa Networks Concerto
APPVersa-Networks12.1.212.2.011.4.0 – 12.1.2 (excl.)
CISA KEV — detailsi
- Vendori
- Versa
- Producti
- Concerto
- Added to KEVi
- January 22, 2026
- Remediation deadline (US Federal)i
- February 12, 2026(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.
Related vulnerabilities
Versa Concerto SD-WAN: Authentication Bypass + RCE przez TOCTOU Race Condition
The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escap...
Versa Director: domyślne dane uwierzytelniające umożliwiają pełny dostęp
Versa Director: domyślne hasło PostgreSQL umożliwia nieautoryzowany dostęp
Command injection w Versa Director umożliwiający RCE