CVE-2025-34027: Versa Concerto Authentication Bypass File Write Remote Code Execution
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race condition to achieve remote code execution via path loading manipulation, allowing an unauthenticated actor to achieve remote code execution (RCE).This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34027?
The severity of CVE-2025-34027 is considered high due to the potential for unauthorized access to administrative endpoints.
How do I fix CVE-2025-34027?
To fix CVE-2025-34027, update the Versa Concerto software to a version later than 12.2.0.
What is the impact of CVE-2025-34027?
The impact of CVE-2025-34027 allows attackers to bypass authentication and gain access to sensitive administrative functions.
Which versions of Versa Concerto are affected by CVE-2025-34027?
Versions of Versa Concerto from 12.1.2 to 12.2.0 are affected by CVE-2025-34027.
Is there a workaround for CVE-2025-34027?
Currently, there are no documented workarounds for CVE-2025-34027, so patching is recommended.