The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
History

Fri, 23 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Versa-networks
Versa-networks concerto
CPEs cpe:2.3:a:versa-networks:concerto:*:*:*:*:*:*:*:*
cpe:2.3:a:versa-networks:concerto:12.1.2:-:*:*:*:*:*:*
cpe:2.3:a:versa-networks:concerto:12.2.0:*:*:*:*:*:*:*
Vendors & Products Versa-networks
Versa-networks concerto
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 23 Jan 2026 15:15:00 +0000


Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

kev

{'dateAdded': '2026-01-22T00:00:00+00:00', 'dueDate': '2026-02-12T00:00:00+00:00'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Nov 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Versa
Versa concerto
CPEs cpe:2.3:a:versa:concerto:*:*:*:*:*:*:*:*
Vendors & Products Versa
Versa concerto

Tue, 23 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Tue, 23 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288

Thu, 22 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 May 2025 22:15:00 +0000

Type Values Removed Values Added
Description The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
Title Versa Concerto Actuator Authentication Bypass Information Leak
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-05-21T22:04:58.832Z

Updated: 2026-01-23T14:34:06.013Z

Reserved: 2025-04-15T19:15:22.545Z

Link: CVE-2025-34026

cve-icon Vulnrichment

Updated: 2025-05-22T15:22:12.724Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-21T22:15:50.510

Modified: 2026-01-23T18:39:24.063

Link: CVE-2025-34026

cve-icon Redhat

No data.