Description
Versa would like to issue this advisory for buffer overflow vulnerability in the IPsec implementation on VOS, aka Versa FlexVNF. When a maliciously crafted IKE Auth packet is sent to VOS, the vsmd process crashes, thereby resulting in a Denial of Service. An attacker can create a Denial-of-Service attack on the VOS appliances by crafting a malicious IKE Auth packet and sending it to the WAN interfaces on the VOS.
During the IKE Authentication phase, if the IKE SA negotiation fails, and the size of the Remote ID is larger than the buffer size used to process the Remote ID, it will result in a crash of the vsmd process on the VOS appliance.
VOS nodes configured with IPsec VPN profiles of type controller-staging-sdwan or remote-access-server using a WAN interface as the IPsec endpoint are vulnerable. (IPsec profiles configured with an overlay interface as the IPsec endpoint are not affected.) This configuration typically applies to all Controllers, Hub Controllers, and SSE Gateways. Additionally, site-to-site VPN profiles configured without a peer IP address, hostname, or FQDN are also vulnerable.
The VOS nodes listed above are not vulnerable if they are not accessible from the Internet.
Severity
CRITICAL
Weakness Type
CWE-121: Stack-based buffer overflow
Exploitation Status
Versa Networks is aware of the malicious IPsec packets originating from the following source IP blocks at this time.
45.142.193.0/24, 102.135.43.0/24, 102.135.44.0/23, 102.135.46.0/24
Product Status
|
Version |
Affected |
Unaffected |
|
21.2.3 |
All versions are affected | EOS. Please upgrade to 22.1.4. |
|
22.1.2 |
All version are affected. |
July 26, 2026, or later. |
|
22.1.3 |
All versions are affected |
July 26, 2026, or later. |
|
22.1.4 |
All versions are affected |
July 26, 2026, or later. |
|
23.1.X |
All versions are affected |
Software will be made available by August 1, 2026. |
Workarounds or Mitigation
Permanent Resolution
Upgrade to a software release that includes the fix for this vulnerability. After the upgrade is completed, the mitigations described above are no longer required.
Software Download Links
To download and install the Hotfix with the patch, log in to the Support portal, where you can view the release notes and access the download link.
For 22.1.3
For 22.1.4: