Answer in brief
CVE-2024-39717 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Versa/Director (generic), versa-networks/versa_director (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Versa/Director (generic), versa-networks/versa_director (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Versa/Directorgeneric | 21.2.2 || >=21.2.3 before 2024-06-21 <21.2.3 before 2024-06-21 || 22.1.1 || 22.1.2 before 2024-06-21 || 22.1.3 before 2024-06-21 | 21.2.3 before 2024-06-21 |
| versa-networks/versa_directorgeneric | 21.2.2 || >=21.2.3 <21.2.3_2024-06-21 || 22.1.1 || >=22.1.2 <22.1.2_2024-06-21 || >=22.1.3 <22.1.3_2024-06-21 | 21.2.3_2024-06-21, 22.1.2_2024-06-21, 22.1.3_2024-06-21 |
Published upstream
Aug 22, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Aug 23, 2024
Evidence: source:kev:kev:kev:recordThe Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-39717 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps Versa/Director (generic), versa-networks/versa_director (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Versa/Director (generic), versa-networks/versa_director (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Versa/Directorgeneric | 21.2.2 || >=21.2.3 before 2024-06-21 <21.2.3 before 2024-06-21 || 22.1.1 || 22.1.2 before 2024-06-21 || 22.1.3 before 2024-06-21 | 21.2.3 before 2024-06-21 |
| versa-networks/versa_directorgeneric | 21.2.2 || >=21.2.3 <21.2.3_2024-06-21 || 22.1.1 || >=22.1.2 <22.1.2_2024-06-21 || >=22.1.3 <22.1.3_2024-06-21 | 21.2.3_2024-06-21, 22.1.2_2024-06-21, 22.1.3_2024-06-21 |
Published upstream
Aug 22, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Aug 23, 2024
Evidence: source:kev:kev:kev:recordThe Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be mis-used to upload a malicious file ending with .png extension to masquerade as image file. This is possible only after a user with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin has successfully authenticated and logged in.
Quoted source text, attributed separately from HOL analysis.