THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-24288 (CRITICAL 9.8) — The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the

[NVD] CVE-2025-24288 (CRITICAL 9.8) — The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the

lownvdPublished 2025-06-19

CVE-2025-24288 CVSS: 9.8 CRITICAL Published: 2025-06-19T00:15:22.323

The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other services.

V

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-24288