EXECUTIVE SUMMARY
A zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717, has been actively exploited in the wild. This vulnerability is present in Versa software-defined wide area network (SD-WAN) applications. Versa Director servers are crucial for managing network configurations for clients running SD-WAN software, making them a valuable target for threat actors. These servers, often used by internet service providers (ISPs) and managed service providers (MSPs), enable the orchestration of Versa's SD-WAN functionality, placing them at the core of enterprise network management.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717, has been actively exploited in the wild. This vulnerability is present in Versa software-defined wide area network (SD-WAN) applications. Versa Director servers are crucial for managing network configurations for clients running SD-WAN software, making them a valuable target for threat actors. These servers, often used by internet service providers (ISPs) and managed service providers (MSPs), enable the orchestration of Versa's SD-WAN functionality, placing them at the core of enterprise network management.[emaillocker id="1283"]
The exploitation of CVE-2024-39717 involves the deployment of a web shell named "VersaMem." This custom-tailored JAR web shell is designed to interact with Versa Director servers, primarily serving to intercept and harvest credentials, enabling unauthorized access to downstream networks. The web shell leverages the Java Instrumentation API and Javassist to dynamically modify Java code in memory, allowing the threat actors to avoid detection. It operates entirely in memory, loading additional Java modules without leaving traces on disk, making it particularly challenging to detect and mitigate. Initial access is gained through an exposed management port intended for high-availability (HA) pairing of Director nodes, leading to the deployment of VersaMem and subsequent exploitation of the affected systems.
In conclusion, the exploitation of this vulnerability poses significant risks to organizations relying on Versa Director servers, particularly those in the ISP, MSP, and IT sectors. The deployment of the VersaMem web shell allows threat actors to gain deep access to network configurations and potentially pivot into downstream networks. Given the severity of the vulnerability and the sophistication of the attack, it is crucial for affected entities to upgrade to the software version and implement the recommended mitigation steps to protect their systems from ongoing exploitation.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command and Scripting Interpreter |
| T1203 | Exploitation for Client Execution | |
| Defense Evasion | T1078 | Valid Accounts |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1003 | OS Credential Dumping |
| Command and Control | T1071 | Application Layer Protocol |
| Impact | T1486 | Data Encrypted for Impact |
| T1498 | Network Denial of Service |
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://arstechnica.com/security/2024/08/hackers-infect-isps-with-malware-that-steals-customers-credentials/