THREAT OPS › Threat News › [NVD] CVE-2025-24288 (CRITICAL 9.8) — The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the
[NVD] CVE-2025-24288 (CRITICAL 9.8) — The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the
CVE-2025-24288 CVSS: 9.8 CRITICAL Published: 2025-06-19T00:15:22.323
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other services.
V
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2025-24288cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-24288