CVE-2019-25029 - CVE House
Back to Database
Status published Critical CVE-2019-25029

In Versa Director, the command injection is an attack in...

Vulnerability Description

In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25029

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Versa Director
Vulnerable Versions:
Fixed Versions: 16.1R2S11, 20.2.2, 21.1.1, 21.2.1

Timeline

Official Publish: May 26th, 2021
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)