Versa Director Zero Day Exploitation
Volt Typhoon Campaign, CVE-2024-39717, and MSP/ISP Trust-Path Risk
Research Framing
| Field | Value | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Versa Director Zero Day Exploitation: what the 2024 campaign established, which technical conditions enabled it, how VersaMem changes the investigation, and how MSPs or ISPs should scope downstream client risk. | ||||||||||||||||||||||||||||||
| Interpreted Questions | Which Versa Director versions and management paths were exposed? Was port 4566 or another high-availability management interface reachable from untrusted networks? Did the environment show a disguised PNG/JAR upload, in-memory VersaMem behavior, credential interception, anomalous accounts, or SOHO-device traffic? Which provider and client credentials or control paths were reachable? What supports Volt Typhoon attribution, and what remains organization-specific? | ||||||||||||||||||||||||||||||
| Initial Observations | The retained sources describe a targeted—not mass—campaign against a small observed set of ISP, MSP, and IT-sector Versa Director systems. The vulnerability record describes a dangerous file upload available to specific privileged provider administrators, while Versa and Black Lotus Labs explain that missing firewall and hardening controls exposed a management path used for initial access. VersaMem then operated largely in memory, intercepted plaintext credentials, and supported follow-on code execution, making patch status alone insufficient for retrospective scoping.1, 2, 3, 4, 5 | ||||||||||||||||||||||||||||||
| Source Coverage |
| ||||||||||||||||||||||||||||||
| Evidence Boundary | MITRE C0039 organizes the campaign and ATT&CK mappings; Black Lotus Labs supplies the primary network-telemetry, malware-analysis, observed-victim-set, and moderate-confidence attribution record. NVD and CISA KEV control the vulnerability and active-exploitation status. Versa controls product versions, hot-fix boundaries, hardening, and remediation. MITRE G1017, Microsoft, and the CISA-led joint advisory provide broader Volt Typhoon context and must not be treated as proof that every broader actor behavior occurred in a particular Director incident. |
Campaign Snapshot
Campaign
C0039
MITRE tracks this as the Versa Director Zero Day Exploitation campaign.
CVE
CVE-2024-39717
Versa Director dangerous file type upload vulnerability in the CISA KEV catalog.
Window
Jun-Aug 2024
MITRE's first- and last-seen period for this campaign.
Trust Path
MSP / ISP
Director management infrastructure can create downstream client risk.
1-Topic
This brief covers MITRE ATT&CK campaign C0039: Volt Typhoon's exploitation of Versa Director servers from June through August 2024. The campaign used CVE-2024-39717 against a high-value SD-WAN management plane, with the public record describing credential capture, VersaMem web-shell activity, and risk to ISP and MSP client relationships.1, 2, 3
2-Persona / Audience Lens
CISOs, network and SD-WAN teams, MSP and ISP security leaders, SOC/IR teams, vulnerability-management teams, critical-infrastructure defenders, vendor-risk teams, and cyber-insurance or breach-response advisors. The operational focus is Director inventory, patch and mitigation verification, management-plane exposure, web-shell hunting, credential review, and downstream customer scoping.
3-BLUF
- This was a targeted control-plane intrusion campaign, not indiscriminate mass exploitation: Black Lotus Labs identified five observed victims in ISP, MSP, and IT sectors. The small research set does not reduce the consequence: a compromised Director can expose provider credentials and trusted paths into managed customer networks.1, 2
- The exploit conditions matter as much as the CVE number: The CVE record describes a dangerous file upload available to specific privileged provider administrators. Versa and Black Lotus Labs report that missing firewall and hardening controls exposed a management path used for initial access in observed cases.2, 3, 4
- CVE-2024-39717 is a KEV and requires verified remediation: CISA added the vulnerability to KEV on August 23, 2024. Verify the exact Director image and June 21 hot-fix boundary, apply current vendor hardening, and restrict high-availability management ports to approved Director peers.3, 4, 5
- VersaMem makes a clean file scan insufficient: The custom JAR web shell attached to Tomcat, modified Java behavior in memory, intercepted plaintext credentials, and could load additional code without leaving ordinary Java files behind. Hunt process memory, authentication, temporary files, accounts, and network behavior—not only one filename.1, 2
- Patching does not answer whether credentials or clients were reached: After remediation, determine which users authenticated to the affected Director, whether credentials were captured or reused, and which customer tenants or network-control paths those credentials could access.1, 2, 4
- Keep attribution and downstream impact evidence-bound: MITRE associates C0039 with Volt Typhoon, while Black Lotus Labs assessed the actor link with moderate confidence. Neither campaign attribution nor provider compromise alone proves that a specific downstream customer was accessed.1, 2, 6
4-Executive Summary
MITRE ATT&CK tracks C0039 as a June-through-August 2024 Volt Typhoon campaign against Versa Director systems used by MSPs and ISPs. Black Lotus Labs identified four U.S. and one non-U.S. observed victim and assessed the activity as targeted, with the earliest observed U.S. exploitation on June 12.1, 2
The public vulnerability and campaign records must be read together. NVD describes a dangerous favicon-upload function available after a specific privileged provider-administrator login. Versa and Black Lotus Labs add the campaign condition: missing firewall and system-hardening controls left a high-availability management port exposed, enabling the observed initial-access path.2, 3, 4
After access, the actor deployed VersaMem, a custom JAR web shell designed for Versa Director. It attached to the Tomcat Java process, changed application behavior in memory, intercepted plaintext credentials, stored encrypted results in /tmp/.temp.data, and supported additional in-memory Java modules. This design reduces the value of file-only detection and raises the importance of credential and downstream-session review.1, 2
The response therefore has two tracks: verify the exact fixed release and hardening state, then establish historical compromise and provider-to-client impact. The decision-ready output is an instance-level exposure record, a preserved compromise timeline, an affected-credential list, and a client-by-client reachability and evidence matrix.1, 2, 3, 4, 5
MITRE records the campaign-to-Volt Typhoon relationship; Black Lotus Labs expressed moderate confidence in the attribution. Microsoft and the CISA-led joint advisory supply broader actor context, but their wider critical-infrastructure reporting is not automatic proof of behavior, targeting, or impact in any particular Versa Director incident.1, 2, 6, 7, 8
5-AI Agent Delta Updates
Material deltas change a conclusion, evidence boundary, remediation requirement, or provider/client scoping decision. Routine checks and formatting changes are not counted as intelligence updates.
| Update | Source-backed Change | Why It Matters |
|---|---|---|
| Jul 18, 2026 | The brief now separates the CVE's privileged-upload description from the exposed management-port and missing-hardening conditions documented in the campaign. | Teams can test the actual exploit preconditions instead of treating every Versa Director deployment—or every privileged upload feature—as equivalent exposure.2, 3, 4 |
| Jul 18, 2026 | VersaMem analysis now covers disguised JAR uploads, in-memory Java modification, plaintext credential interception, dynamic module loading, and the limited value of file-only scanning. | Hunting expands from a single filename to process memory, Tomcat behavior, credential use, temporary files, management traffic, and downstream authentication.1, 2 |
| Daily | The PANDA AI Agent checks the retained vendor, government, framework, and primary-research sources; Page Alerts are enabled. | Subscribers should receive notices only when source-backed changes alter a card, conclusion, or evidence boundary.1, 2, 3, 4, 5, 6, 7, 8 |
6-Why It Matters
| Stakeholder | Why This Campaign Matters | Decision It Should Drive |
|---|---|---|
| Executives / boards | Versa Director is a provider control-plane system. Credential theft or unauthorized code there can create a trust and continuity issue across managed customer environments, not only one server. | Require an asset-level exposure finding plus a provider-to-client reachability and credential-impact assessment.1, 2 |
| Network / security | The observed web shell modified Java behavior in memory and captured credentials as users logged in, so traditional file scanning or a clean-looking web root may miss relevant evidence. | Combine patch and firewall validation with memory-aware, authentication, account, Tomcat, temporary-file, and network hunting.2, 4 |
| MSP / ISP / legal | Legitimate provider credentials captured at Director could be used for follow-on access to client infrastructure, but the public campaign record does not establish that every client was reached. | Map each credential and management relationship to reachable clients, then notify or investigate based on evidence and contractual roles.1, 2 |
7-Timeline
| Date / Period | Event / Meaning | Sources |
|---|---|---|
| June 3, 2024 | Black Lotus Labs reports that the VersaMem JAR metadata showed a June 3 build time.2 | 2 |
| June 7, 2024 | The VersaTest.png sample was uploaded to VirusTotal; Black Lotus Labs later identified it as the custom VersaMem JAR web shell.2 | 2 |
| June 12, 2024 | Black Lotus Labs' earliest observed U.S. exploitation involved an ISP; MITRE records the broader campaign as first seen in June.1, 2 | 1, 2 |
| June 21, 2024 | Versa identifies this date as the hot-fix boundary for specified 21.2.3, 22.1.2, and 22.1.3 images; earlier listed images remained affected.3, 4 | 3, 4 |
| July 26–August 9, 2024 | Versa issued customer hardening and zero-day vulnerability bulletins before its public August 26 update.4 | 4 |
| August 23, 2024 | CISA added CVE-2024-39717 to KEV with a September 13 federal remediation deadline.3, 5 | 3, 5 |
| August 26–27, 2024 | Versa published its public security update, followed by Black Lotus Labs' technical campaign and VersaMem analysis.2, 4 | 2, 4 |
| August 2024 | MITRE records August as the last-seen month for C0039 while retaining the campaign and Volt Typhoon relationship.1 | 1 |
8-Incident Response Playbook Ideas
| Phase | Action | Sources |
|---|---|---|
| Inventory the management plane | Identify every Director instance, exact image and hot-fix date, HA peer, public endpoint, management port, administrator role, firewall path, managed tenant, and credential relationship. Record unknowns as investigation gaps.2, 3, 4, 5 | 2, 3, 4, 5 |
| Contain without destroying evidence | Restrict untrusted access to management and HA ports, preserve the Director and relevant memory/log evidence, and follow Versa's current remediation guidance. Coordinate credential rotation so evidence and service continuity are not lost.2, 4, 5 | 2, 4, 5 |
| Hunt beyond the web root | Check the custom-logo directory for non-image PNGs, but also examine Tomcat/Java behavior, /tmp/.temp.data, new accounts, unexpected modules, authentication events, short port-4566 sessions followed by HTTPS, and anomalous provider administration.1, 2, 4 | 1, 2, 4 |
| Scope and rotate exposed credentials | Identify users who authenticated through the affected Director, determine which credentials could have been intercepted, invalidate sessions, rotate supported accounts, and monitor for reuse from SOHO or other unexpected infrastructure.1, 2, 7, 8 | 1, 2, 7, 8 |
| Resolve provider-to-client impact | Map each captured or potentially exposed credential and control-plane permission to reachable customer tenants. Separate plausible reachability, attempted access, successful access, and confirmed change or collection in the client matrix.1, 2 | 1, 2 |
9-Term Glossary
| Term | Meaning Here | Sources |
|---|---|---|
| Versa Director | The centralized management, monitoring, and orchestration system for Versa SD-WAN. Providers may use it to administer multiple customer environments, making it a control-plane asset.2, 4 | 2, 4 |
| SD-WAN | Software-defined wide-area networking: centrally managed network connectivity and policy across locations. Here, the concern is the system that controls that connectivity, not an ordinary user endpoint.1, 2 | 1, 2 |
| CVE-2024-39717 | A dangerous-file upload vulnerability in the Director GUI's favicon customization, available to specified privileged provider-administrator roles; included in CISA KEV after known exploitation.3, 4, 5 | 3, 4, 5 |
| HA management port | A port used for high-availability pairing between approved Director nodes. Black Lotus Labs highlighted port 4566 traffic from non-Versa SOHO devices as a likely successful-exploitation pattern.2, 4 | 2, 4 |
| VersaMem | A custom Java web shell that attached to Tomcat, intercepted plaintext credentials, and loaded additional Java functionality largely in memory.1, 2 | 1, 2 |
| Volt Typhoon | A PRC state-sponsored actor associated by MITRE with C0039. Black Lotus Labs expressed moderate confidence in the campaign attribution; Microsoft and CISA provide broader actor context.1, 2, 6, 7, 8 | 1, 2, 6, 7, 8 |
10-TTPs
| Behavior / ATT&CK | Campaign Mapping | Sources |
|---|---|---|
| T1190 - Exploit Public-Facing Application | MITRE maps CVE-2024-39717 exploitation of Versa Director to initial access and code execution.1 | 1 |
| T1505.003 - Web Shell | MITRE records deployment of VersaMem for follow-on activity. Hunt for anomalous server-side components and management-plane changes.1, 2 | 1, 2 |
| T1056 - Input Capture | MITRE describes credential interception and harvesting from user logins to compromised devices.1 | 1 |
| T1584.008 - Compromise Infrastructure: Network Devices | MITRE reports compromised SOHO devices as infrastructure used to interact with vulnerable Director servers.1, 6 | 1, 6 |
| T1071.001 / T1573.002 - HTTPS C2 | MITRE maps the campaign's HTTPS communications and encrypted channel behavior; use this as a behavioral hunting lead, not a standalone indicator.1 | 1 |
11-Common Questions Q&A
| Question | Source-bound Answer |
|---|---|
| Was CVE-2024-39717 simply an unauthenticated internet upload? | Not according to the CVE description. NVD says the GUI upload function requires a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin login. Versa and Black Lotus Labs separately report that missing firewall and hardening controls exposed a high-availability management path used for initial access in the observed campaign.2, 3, 4 |
| If Director is patched, is the investigation finished? | No. A remediated version closes the known vulnerability, but it does not determine whether exploitation, VersaMem execution, credential interception, account changes, or downstream access occurred earlier.1, 2, 4, 5 |
| Does no suspicious PNG mean no compromise? | No. Invalid PNG files in the custom-logo directory are important leads, but VersaMem's important functions execute in memory. Review Tomcat, Java, authentication, accounts, temporary files, traffic, and credential use as well.2, 4 |
| Does a compromised provider Director mean every client was compromised? | No. It creates a plausible downstream path. Each client conclusion requires evidence about reachable tenants, captured credentials, successful authentication, configuration access, and follow-on activity.1, 2 |
| Does finding CVE exploitation prove Volt Typhoon? | No. MITRE maps the public campaign to Volt Typhoon and Black Lotus Labs assessed the actor link with moderate confidence. A local incident needs its own evidence and should preserve that confidence boundary.1, 2, 6 |
12-CVE / Vulnerability References
The CVE, KEV entry, vendor bulletin, and campaign record answer different questions and should not be collapsed into a single claim.
| Reference | Role | What It Establishes | Limit |
|---|---|---|---|
| CVE-2024-39717 | Vulnerability definition | A dangerous-file upload through Director's favicon customization available to specific privileged provider-administrator roles; affected-version detail and severity metrics. | The CVE description alone does not establish the full initial-access path, actor, or local compromise.3, 4 |
| CISA KEV | Active-exploitation priority | Known exploitation, August 23, 2024 catalog addition, September 13 federal due date, and required vendor mitigation or discontinuation. | KEV status does not prove a particular instance was exploited.3, 5 |
| Versa security bulletin | Product and remediation authority | Affected releases, June 21 hot-fix boundaries, 22.1.4 unaffected status, hardening requirements, and vendor-known exploitation. | Vendor guidance does not replace forensic validation of one environment.4 |
| MITRE C0039 / Black Lotus Labs | Campaign mechanics | Observed exploitation path, VersaMem, credential interception, network behavior, victim-set boundary, and attribution assessment. | Observed cases may not describe every exploit attempt or affected deployment.1, 2 |
13-IOCs / Observables
This public brief retains defensible detection and scoping observables, not raw attacker infrastructure or operational instructions. Validate against owned telemetry before blocking or attributing.
| Observable | Defender Use | Sources |
|---|---|---|
| HA ports 4566 / 4570 reachable from untrusted networks | Reconstruct historical firewall and exposure state. These ports should be limited to approved Director pairing nodes, not arbitrary internet or SOHO sources.2, 4 | 2, 4 |
| Short port-4566 session followed by substantial HTTPS | Black Lotus Labs assessed this sequence from a non-Versa SOHO source as a likely signature of successful exploitation. Correlate source, timing, bytes, and later authentication.1, 2 | 1, 2 |
| Invalid PNG or disguised JAR in custom_logo | Review /var/versa/vnms/web/custom_logo/ for .png files whose MIME type is not image/png, including VersaTest.png or related anomalous uploads. Preserve files and metadata.2, 4 | 2, 4 |
| Unexpected Java/Tomcat in-memory modification | Look for Java instrumentation, dynamic class loading, altered request filtering or authentication behavior, and processes inconsistent with the Director baseline.1, 2 | 1, 2 |
| /tmp/.temp.data and credential interception | VersaMem used this path for encrypted captured credentials. Treat it as a high-priority lead and map affected logins to provider and client access.2 | 2 |
| New accounts, role changes, or unusual privileged sessions | Correlate Director administrator changes and successful logins with exposure and suspected compromise times, then review reuse across customer environments.1, 2, 4 | 1, 2, 4 |
14-Threat Actor Glossary
| Actor / Label | Attribution Boundary | Sources |
|---|---|---|
| Volt Typhoon / C0039 | MITRE explicitly associates Volt Typhoon with the June–August 2024 Versa Director campaign and VersaMem.1, 6 | 1, 6 |
| Black Lotus Labs confidence | The primary research assessed the activity as Volt Typhoon with moderate confidence, based on the campaign's infrastructure, malware, and observed tradecraft.2 | 2 |
| Broader Volt Typhoon tradecraft | Microsoft and the CISA-led joint advisory describe stealth, valid credentials, living-off-the-land activity, compromised SOHO infrastructure, and critical-infrastructure targeting. Use this to shape hypotheses, not to manufacture Versa-specific facts.7, 8 | 7, 8 |
| Attribution boundary | CVE exposure, a web shell, or a suspicious source IP alone does not prove Volt Typhoon. Preserve alternative hypotheses and make organization-specific attribution proportional to the evidence.1, 2, 6 | 1, 2, 6 |
15-Talking Points
| Audience | Decision-ready Point | Sources |
|---|---|---|
| Executive / board | This is a control-plane trust event: the potential blast radius follows provider credentials and managed-customer reach, not merely the number of compromised Director servers.1, 2 | 1, 2 |
| Network / SD-WAN | A green patch dashboard is only half the answer. We also need the historical HA-port, firewall, invalid-upload, Tomcat, account, credential, and downstream-session evidence.2, 3, 4, 5 | 2, 3, 4, 5 |
| SOC / IR | VersaMem was designed to live in the Java process and capture credentials. Hunt behavior and authentication consequences, not only a known hash or PNG filename.1, 2 | 1, 2 |
| MSP / ISP | Build a client-by-client matrix that separates reachability, attempted access, successful login, configuration change, and confirmed impact. Do not declare every managed client compromised by association.1, 2 | 1, 2 |
| Legal / insurance / customer response | Notification and contractual decisions should follow supported provider and client facts: affected asset, exposed credential, reachable tenant, successful access, and resulting change or collection.1, 2, 4 | 1, 2, 4 |
16-Decision Ready Actions
| Decision | Minimum Evidence / Trigger | Likely Owner | Required Output |
|---|---|---|---|
| Open or close historical exposure review | Director version and hot-fix date, management-port exposure—especially 4566/4570—firewall and hardening state, and internet reachability during the campaign window. | Network / vulnerability management | Instance-level exposure register with evidence gaps and accountable owners.2, 3, 4, 5 |
| Declare or expand an incident | Suspicious invalid PNG/JAR, VersaMem indicators, /tmp/.temp.data, new accounts, anomalous Tomcat/Java behavior, SOHO-to-4566 then HTTPS traffic, or unexplained privileged logins. | SOC / incident response | Preserved evidence, compromise timeline, credentials at risk, and confidence-rated findings.1, 2, 4 |
| Rotate provider or client credentials | Evidence that credentials were entered into a compromised Director, stored in /tmp/.temp.data, or used from unexpected infrastructure. | Identity / network operations | Credential inventory, revocation sequence, session invalidation, and post-rotation monitoring.1, 2 |
| Investigate or notify managed clients | A captured credential, management relationship, configuration path, or successful access event maps the compromised Director to a client environment. | MSP/ISP leadership, legal, client response | Client-by-client reachability, evidence, communication, contractual, and notification matrix.1, 2 |
17-Exploitable Technology Risks
| Technology / Trust Path | Risk / Defensive Priority | Sources |
|---|---|---|
| Centralized SD-WAN control plane | Director can administer network policy and connectivity across provider-managed environments. Treat it as a tier-zero network-management asset with segmentation, strong identity, and defensible logging.1, 2, 4 | 1, 2, 4 |
| High-availability management trust | HA ports intended for approved Director peers became a critical exposure path when reachable from untrusted SOHO devices. Enforce explicit peer allowlists and audit them continuously.2, 4 | 2, 4 |
| Privileged dangerous-file upload | CVE-2024-39717 combines a privileged customization feature with dangerous file handling. Review both software state and how provider-admin privileges and management access are governed.3, 4, 5 | 3, 4, 5 |
| In-memory Java persistence and execution | VersaMem altered Tomcat behavior without relying on ordinary on-disk Java files, weakening file-only prevention and detection assumptions.1, 2 | 1, 2 |
| Provider credential reuse and client reach | Credentials captured at the management plane may carry legitimate access into customer environments. Reduce privilege, isolate tenants, and monitor provider identities end to end.1, 2, 7, 8 | 1, 2, 7, 8 |
19-Tier 0 Through Tier 8 Source Summary
| Tier / Class | Retained Sources | What They Control | Boundary |
|---|---|---|---|
| Tier 0 — Government / vendor | NVD, CISA KEV, Versa security bulletin | CVE definition, KEV status, affected releases, hot-fix boundaries, hardening, remediation, and vendor-known exploitation. | Do not independently prove local compromise or campaign attribution.3, 4, 5 |
| Tier 0 — Framework | MITRE C0039 and Volt Typhoon G1017 | Canonical campaign period, actor relationship, VersaMem, and normalized ATT&CK behaviors. | Framework mappings organize retained reporting; they do not replace local evidence.1, 6 |
| Tier 1 — Primary research | Lumen Black Lotus Labs | Network-telemetry observations, five-victim research set, exploit sequence, VersaMem reverse engineering, indicators, and moderate-confidence attribution. | Observed cases and telemetry visibility may not represent every intrusion.2 |
| Tier 1 — Actor context | Microsoft Threat Intelligence and CISA-led joint advisory | Broader Volt Typhoon targeting, compromised SOHO infrastructure, stealth, credential use, and critical-infrastructure context. | Broader actor tradecraft must not be imported as a fact in every Versa case.7, 8 |
| Tiers 6–8 — Leads only | No social posts, unsourced lists, or secondary victim counts retained as controlling evidence | Lead generation only. | Requires validation against a primary disclosure, authoritative source, or owned telemetry.1, 2, 4 |
20-Source Reconciliation
| Issue | How IntelliOS Handles It | Sources |
|---|---|---|
| CVE description versus observed initial access | NVD describes a privileged GUI upload. Versa and Black Lotus Labs report that missing firewall and hardening controls exposed a management port used for initial access. IntelliOS retains both facts and does not flatten the chain into an unauthenticated upload claim.2, 3, 4 | 2, 3, 4 |
| Affected-version and hot-fix record | NVD's maintained affected-record and Versa's bulletin agree on the listed 21.2.x/22.1.x exposure boundaries and June 21 hot fixes. Current vendor guidance controls remediation when records change.3, 4 | 3, 4 |
| Actor attribution confidence | MITRE maps C0039 to Volt Typhoon. Black Lotus Labs expressed moderate confidence. Microsoft and CISA add broad actor context; IntelliOS preserves the campaign link without converting wider tradecraft into local fact.1, 2, 6, 7, 8 | 1, 2, 6, 7, 8 |
| Observed victim set versus complete population | Black Lotus Labs reported five observed victims within its visibility, while Versa confirmed exploitation in at least one known instance. Neither source claims a complete affected-party inventory.2, 4 | 2, 4 |
| Provider exposure versus client compromise | Credential capture creates a credible downstream path. Only provider and client evidence can establish which tenants were reachable, attempted, accessed, changed, or otherwise affected.1, 2 | 1, 2 |
21-About the Contributors
| Contributor | Role in This Brief | Sources |
|---|---|---|
| MITRE ATT&CK | Canonical public campaign and actor mapping for C0039, ATT&CK techniques, and VersaMem.1, 6 | 1, 6 |
| Lumen Black Lotus Labs | Primary network-telemetry and malware-analysis source for exploit timing, observed sectors and victim set, VersaMem behavior, indicators, response guidance, and moderate-confidence attribution.2 | 2 |
| Versa Networks | Product authority for the vulnerability, affected and remediated releases, hardening requirements, customer bulletin history, and vendor-known exploitation status.4 | 4 |
| NIST NVD / CISA KEV | Authoritative vulnerability description, privilege condition, affected-version record, known-exploitation priority, due date, and required action.3, 5 | 3, 5 |
| CISA-led joint advisory | Broader government-validated Volt Typhoon critical-infrastructure, credential, SOHO-infrastructure, and mitigation context.8 | 8 |
| Microsoft Threat Intelligence | Primary broader actor research on stealth, valid credentials, living-off-the-land activity, and compromised SOHO infrastructure.7 | 7 |
22-Real World Examples
| Observed Example | Source-backed Fact | Operational Lesson |
|---|---|---|
| Small, targeted provider set | Black Lotus Labs identified four U.S. and one non-U.S. victim in ISP, MSP, and IT sectors, with earliest observed U.S. exploitation on June 12, 2024. | Treat the campaign as targeted and high-consequence; do not describe it as indiscriminate mass exploitation.2 |
| SOHO-to-management-port sequence | Compromised SOHO devices made short TCP sessions to port 4566 followed by substantial HTTPS sessions over port 443. | Hunt for the sequence and validate whether HA management ports accepted traffic from non-Versa nodes.1, 2 |
| In-memory credential interception | VersaMem attached to Tomcat, modified Java behavior in memory, intercepted plaintext credentials, encrypted them, and wrote them to /tmp/.temp.data. | File-only scanning is insufficient; include memory, Java/Tomcat, temporary-file, and credential-use evidence.1, 2 |
| Hardening failure as exploit condition | Versa said impacted customers had not implemented its firewall and system-hardening guidance, leaving a management port exposed. | Verify both the patched release and longstanding firewall/hardening controls; one without the other is an incomplete assurance.4 |
23-Public Victims / Disclosure Matrix
The retained public record supports a bounded observed victim set, not a complete public victim inventory. Provider compromise and downstream client impact must remain separate categories.
| Disclosure Class | What the Public Record Says | Appropriate Use | Limit |
|---|---|---|---|
| Primary research victim set | Black Lotus Labs reported four U.S. and one non-U.S. victim across ISP, MSP, and IT sectors. | Establish observed targeting and campaign scale within that research visibility. | Organizations were not named in the retained source and the set is not necessarily complete.2 |
| Vendor-confirmed exploitation | Versa states that the vulnerability was exploited in at least one known instance by an advanced persistent threat actor. | Confirm real-world exploitation and remediation urgency. | Does not identify every affected organization or every downstream client.4 |
| Downstream client exposure | MITRE and Black Lotus Labs describe credential capture intended to enable follow-on access to service-provider clients. | Prioritize client reachability, credential, and authentication review. | A plausible or intended path is not proof that a particular client was accessed.1, 2 |
| Organization-specific impact | Must be established from the provider's Director, identity, network, tenant, configuration, and client evidence. | Controls incident, notification, contractual, regulatory, and insurance decisions. | Cannot be inferred solely from product use, KEV status, or actor attribution.1, 2, 4, 5 |
24-KEV and CVE Details
| Item | Status | Response Meaning | Boundary |
|---|---|---|---|
| CVE-2024-39717 / KEV | High-severity dangerous-file upload; added to CISA KEV August 23, 2024 with a September 13 due date. | Apply the Versa remediation and hardening guidance or discontinue use when mitigation is unavailable; investigate historical exposure. | Known exploitation does not establish compromise of one instance.3, 4, 5 |
| Privilege condition | The GUI upload requires a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin login. | Review privileged provider accounts, authentication history, role assignments, and whether the exposed management path bypassed expected GUI controls. | Do not inaccurately describe the CVE record as a simple unauthenticated favicon upload.3, 4 |
| Affected releases | 21.2.2 and 22.1.1 affected; specified 21.2.3, 22.1.2, and 22.1.3 images before the June 21 hot fix affected; 22.1.4 unaffected. | Record the exact installed image and hot-fix date; verify upgrade against the current vendor bulletin. | Version status answers vulnerability exposure, not whether VersaMem or downstream access occurred.3, 4 |
25-MITRE ATT&CK Lifecycle Mapping
| Lifecycle / ATT&CK | Campaign Behavior | Evidence to Seek | Defensive Breakpoint |
|---|---|---|---|
| Infrastructure — T1584.008 | Use compromised SOHO network devices to approach Director systems and blend with ordinary internet traffic. | Source IP ownership, router reputation, prior sessions, and non-Versa nodes reaching management ports. | Block untrusted management traffic, restrict HA peers, and baseline approved node relationships.1, 2, 6, 7, 8 |
| Initial Access — T1190 | Exploit CVE-2024-39717 through an exposed and insufficiently hardened Director management path. | Version/hot-fix state, firewall rules, ports 4566/4570, invalid PNG/JAR files, upload and account activity. | Patch, harden, remove unnecessary internet exposure, and allow HA traffic only between approved Director nodes.1, 2, 3, 4, 5 |
| Persistence / Execution — T1505.003 | Deploy VersaMem and dynamically load Java functionality inside the Tomcat process. | Tomcat/Java memory and process behavior, suspicious files, requests carrying web-shell parameters, and unexpected code-loading artifacts. | Memory-aware response, process baselining, file validation, and restricted application write/load paths.1, 2 |
| Credential Access — T1056 | Hook Director authentication to intercept plaintext credentials and store encrypted output in /tmp/.temp.data. | Temporary file, authentication timing, affected users, subsequent logins, role changes, and client reachability. | Rotate exposed credentials, invalidate sessions, require strong MFA where supported, and monitor post-reset use.1, 2 |
| Command and Control — T1095 / T1071.001 / T1573.002 | Use a short nonstandard TCP session followed by HTTPS communications for control and follow-on activity. | Port 4566 connection followed by moderate-to-large port 443 sessions, SOHO origins, timing, and byte volume. | Network detection for the sequence, strict peer allowlists, egress controls, and rapid containment of anomalous Director traffic.1, 2 |
| Follow-on Access | Use captured provider credentials and control-plane trust to attempt access to service-provider clients. | Client logins, tenant access, configuration changes, session origins, and provider credential reuse. | Credential isolation, least privilege, tenant segmentation, client-specific monitoring, and coordinated notification.1, 2 |
26-Source Weighting / Relevance
| Source | Weight | Claims It Controls | Known Limits |
|---|---|---|---|
| MITRE C0039 | Controlling for framework | Campaign period, Volt Typhoon relationship, VersaMem, and ATT&CK behavior normalization. | Primarily derives the campaign record from Black Lotus Labs and does not prove local impact.1 |
| Lumen Black Lotus Labs | High / primary | Network telemetry, exploit sequence, five-victim observed set, malware analysis, indicators, mitigations, and moderate-confidence attribution. | Visibility is bounded to observed telemetry and cases; the original URL now redirects on Lumen's site.2 |
| NVD and CISA KEV | Controlling for vulnerability | CVE description, privilege condition, affected releases, active exploitation, due date, and required action. | Do not establish actor identity, full exploit chain, or local compromise.3, 5 |
| Versa security bulletin | Controlling for product | Affected and remediated releases, hardening requirements, product-specific checks, and vendor-known exploitation. | Vendor scope and testing statements do not replace independent incident response.4 |
| MITRE G1017, Microsoft, CISA joint advisory | Contextual | Broader Volt Typhoon targeting, stealth, SOHO infrastructure, credential use, and critical-infrastructure risk. | Broader actor behavior must not be asserted as observed in every Director incident.6, 7, 8 |
27-Additional IntelliOS Threat Intel Products on This Topic
CARDS Campaign
Versa Director Zero Day Exploitation Campaign Card
Canonical campaign record with MITRE C0039 data, CVE linkage, source citations, and the linked PANDA flash brief.
CARDS Actor
Volt Typhoon Actor Card
Actor profile for aliases, targeting context, source links, and the campaign relationship.
28-Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
29-Citations
| # | Tier | Publisher | Published | Why Used | Source |
|---|---|---|---|---|---|
| 1 | Tier 0 - Authoritative framework | MITRE ATT&CK | Updated September 2024 | Canonical public campaign record: Volt Typhoon attribution, June-August 2024 window, credential capture, VersaMem, and ATT&CK technique mappings. | Versa Director Zero Day Exploitation, Campaign C0039 |
| 2 | Tier 1 - Primary technical research | Lumen Black Lotus Labs | August 27, 2024 | Technical campaign analysis for active exploitation, provider/SD-WAN management-plane significance, and defender response context. | Taking The Crossroads: The Versa Director Zero-Day Exploitation |
| 3 | Tier 0 - Government vulnerability record | NIST NVD | August 2024; modified June 2026 | Authoritative CVE details, affected configuration information, vendor-advisory references, and CISA KEV status. | CVE-2024-39717 |
| 4 | Tier 0 - Vendor advisory | Versa Networks | August 2024 | Vendor mitigation and product-specific vulnerability guidance, referenced by NVD. | Versa Security Bulletin: Update on CVE-2024-39717 |
| 5 | Tier 0 - Government advisory | CISA | August 23, 2024 | CISA KEV inclusion and required-action context. | Known Exploited Vulnerabilities Catalog - CVE-2024-39717 |
| 6 | Tier 0 - Authoritative framework | MITRE ATT&CK | Updated April 2026 | Actor record tying Volt Typhoon to C0039 and its broader documented techniques. | Volt Typhoon, Group G1017 |
| 7 | Tier 1 - Primary threat intelligence | Microsoft Threat Intelligence | May 24, 2023 | Broader actor context on critical-infrastructure targeting, stolen credentials, stealth, living-off-the-land activity, and compromised SOHO devices; not treated as proof of every behavior in C0039. | Volt Typhoon targets US critical infrastructure with living-off-the-land techniques |
| 8 | Tier 0 - Joint government advisory | CISA, NSA, FBI and partners | February 7, 2024 | Government-validated broader Volt Typhoon context for persistent critical-infrastructure access, valid credentials, compromised SOHO infrastructure, behavioral hunting, and management-interface hardening; not a Versa-campaign victim record. | PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure |
30-Version Change Log
| Version | Date | Changes |
|---|---|---|
| v1.1 | Jul 18, 2026 | Completed a 32-card FortiBleed-standard review. Rebuilt Research Framing; separated duplicated response, CVE/KEV, disclosure, lifecycle, and source cards; clarified the privileged-upload and exposed-management-port conditions; expanded VersaMem detection, provider-to-client scoping, attribution, and source-weighting guidance; enabled Page Alerts and the dedicated FORGE AI Agent listing. |
| v1.0 | Jul 11, 2026 | Initial source-backed IntelliOS Flash Threat Intel Brief with reciprocal CARDS links, CVE/KEV context, ATT&CK mappings, and provider-management-plane response guidance. |
