The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host access depending on the host operating system configuration.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
History

Thu, 22 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 21 May 2025 23:15:00 +0000

Type Values Removed Values Added
Title Versa Concerto Actuator Insecure Docker Mount Container Escape Versa Concerto Insecure Docker Mount Container Escape

Wed, 21 May 2025 22:30:00 +0000

Type Values Removed Values Added
Description The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerability caused by unsafe default mounting of host binary paths that allow the container to modify host paths. The escape can be used to trigger remote code execution or direct host access depending on the host operating system configuration.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
Title Versa Concerto Actuator Insecure Docker Mount Container Escape
Weaknesses CWE-732
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-05-21T22:11:32.081Z

Updated: 2025-05-28T03:56:02.808Z

Reserved: 2025-04-15T19:15:22.545Z

Link: CVE-2025-34025

cve-icon Vulnrichment

Updated: 2025-05-22T15:53:41.586Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-21T23:15:54.827

Modified: 2025-05-23T15:55:02.040

Link: CVE-2025-34025

cve-icon Redhat

No data.