FortiGuard Outbreak Alert: Versa Concerto SD-WAN Authentication Bypass
| Description | This article describes a vulnerability with Versa Concerto SD-WAN Authentication Bypass.
Versa Concerto is a centralized platform that automates and manages the deployment, configuration, and monitoring of Versa SD-WAN and SASE (Secure Access Service Edge) solutions.
CVE-2025-34025 is a privileged escalation vulnerability in Versa Concerto Docker container which allows an attack inside the container to 'escape' and execute code on the host system. CVE-2025-34027 is an authentication bypass vulnerability in Traefik component of Versa Concerto which allows unauthenticated attacker to upload malicious files and execute arbitrary code on the system.
For affected and fixed product versions, refer to the Versa security advisory links below: | ||||||
| CVE ID | |||||||
| NDR Cloud Detection Rule | FortiNDR Cloud v26.1.a+.
| ||||||
| Playbook | N/A. | ||||||
| Threat Hunting | FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for 'Versa Concerto Improper Authentication Vulnerability' related activities. IOC source: Versa Concerto SD-WAN Authentication Bypass | Indicators of Compromise. All IOCs relating to 'Versa Concerto SD-WAN Authentication Bypass' have been added to Threat Intelligence Intel. | ||||||
| Suricata Coverage | N/A. | ||||||
| Other Fortinet Products | For more details regarding mitigating the vulnerability by utilizing Fortinet products, refer to Versa Concerto SD-WAN Authentication Bypass. |
