PT-2025-22439 · Versa · Versa Concerto Sd-Wan

Harsh Jaiswal

+3

·

Published

2025-05-21

·

Updated

2026-03-05

·

CVE-2025-34025

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Versa Concerto versions 12.1.2 through 12.2.0
Description The Versa Concerto SD-WAN orchestration platform contains a flaw related to improper permission assignment for a critical resource during certificate signing request validation. This can lead to privilege escalation and container escape. The unsafe default mounting of host binary paths allows a container to modify host paths. Successful exploitation of this issue may allow an attacker to execute arbitrary code or gain direct access to the host, depending on the host operating system configuration.
Recommendations Versions 12.1.2 through 12.2.0 should be updated when a patch becomes available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-06721
CVE-2025-34025

Affected Products

Versa Concerto Sd-Wan