CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2025-34026

CVSS 9.2v4.0pub. 2025-05-21upd. 2026-01-23

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

🤖 AI Analysis
How it works

Incorrect Traefik reverse proxy configuration allows an attacker to bypass authentication mechanisms and gain direct access to internal administrative endpoints. In particular, the internal Actuator endpoint becomes accessible, which can expose sensitive operational data such as heap dumps and trace logs. Access to these resources does not require any credentials or user interaction.

Impact

A remote attacker without authentication can gain access to sensitive internal system data, including memory dumps and logs, which may lead to disclosure of configuration data, credentials, or other critical information stored in the platform's memory. It is also possible to leverage the obtained information for subsequent attacks on the infrastructure.

Mitigation & patch

Apply patches available from the vendor immediately in accordance with references published on the Versa Networks security portal (security-portal.versa-networks.com). Until the fix is implemented, it is recommended to restrict network access to Concerto platform administrative endpoints using firewall or ACL rules, and monitor network traffic for unauthorized access attempts to Actuator endpoints.

Who is affected

Versa Concerto versions 12.1.2 through 12.2.0 inclusive. The vendor indicates that additional versions may also be vulnerable.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Versa Networks Concerto

    APP
    Versa-Networks
    12.1.212.2.011.4.0 – 12.1.2 (excl.)

CISA KEV — detailsi

Vendori
Versa
Producti
Concerto
Added to KEVi
January 22, 2026
Remediation deadline (US Federal)i
February 12, 2026(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 12 lutego 2026
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-34027CRITICAL10.0PL ✓same product

Versa Concerto SD-WAN: Authentication Bypass + RCE przez TOCTOU Race Condition

CVE-2025-34025HIGH8.6same product

The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escap...

CVE-2025-24288CRITICAL9.8PL ✓same vendor

Versa Director: domyślne dane uwierzytelniające umożliwiają pełny dostęp

CVE-2024-42450CRITICAL10.0PL ✓same vendor

Versa Director: domyślne hasło PostgreSQL umożliwia nieautoryzowany dostęp

CVE-2019-25029CRITICAL9.8PL ✓same vendor

Command injection w Versa Director umożliwiający RCE