THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-45229 (MEDIUM 6.6) — The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one o

[NVD] CVE-2024-45229 (MEDIUM 6.6) — The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one o

lownvdPublished 2024-09-20

CVE-2024-45229 CVSS: 6.6 MEDIUM Published: 2024-09-20T19:15:16.080

The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by injecting invalid a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-45229