CVE-2025-34026
CISA 기관 조치 기한: 2026-02-12
Versa Concerto
Qualys 위협 인텔 · 심각도 5/5 · QID 732555 · CGI
공개 익스플로잇
측면이동
쉬운 악용
대량 데이터 유출
서비스 거부
패치 없음
웜 전파
고위험 예측
권한상승
인증 불필요
원격코드실행
CISA KEV
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.
KEV 필수 조치: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.