← Back to CVE intelligence
CVE intelligenceCISA KEV

CVE-2024-39717

Versa Director Dangerous File Type Upload Vulnerability

Published Aug 22, 2024Sources checked Sep 12, 2026
7.2HIGHCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2024-39717 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Versa Director.

  • Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA KEVListedObserved exploitation
EPSS4.0%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors1Source-linked actor relationships
Overview

What is CVE-2024-39717?

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.