北京赛克艾威科技有限公司 2024-08-23
The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider\-Data\-Center\-Admin or Provider\-Data\-Center\-System\-Admin privileges to customize the user interface. The “Change Favicon” \(Favorite Icon\) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog