Director
This hub aggregates every CVE we track for Director, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
28
CVEs tracked
5
Critical
10
High
1
In CISA KEV
Severity distribution
MEDIUM13HIGH10CRITICAL5
Monthly trend
1
0
1
0
0
0
0
0
0
9
0
0
0
0
0
0
3
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Director.
- CVE-2025-46066An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges9.9
- CVE-2025-46068An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism8.8
- CVE-2025-46067An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file8.2
- CVE-2025-24288The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the sa...9.8
- CVE-2025-24291The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. ...6.1
- CVE-2025-23171The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allo...7.2
- CVE-2024-45208The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availabilit...9.8
- CVE-2025-23168The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input wh...6.3
- CVE-2025-23172The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can b...7.2
- CVE-2025-23173The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and a...7.5
- CVE-2025-23169The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not prop...6.1
- CVE-2025-23170The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connec...6.7
- CVE-2024-42450The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a co...10.0
- CVE-2024-45229The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. Howe...6.6
- CVE-2024-39717The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Cent...KEV7.2
Product normalization is registry-driven with AI assist and human review. How it works