THREAT OPS › Threat News › [NVD] CVE-2024-45229 (MEDIUM 6.6) — The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one o
[NVD] CVE-2024-45229 (MEDIUM 6.6) — The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one o
CVE-2024-45229 CVSS: 6.6 MEDIUM Published: 2024-09-20T19:15:16.080
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by injecting invalid a
MITRE ATT&CK techniques
- Device RegistrationT1098.005
Indicators of compromise
- CVE-2024-45229cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-45229