VRSA-EXT-008-2026-0001: Advising of Denial-of-Service Attack on VOS using malicious IKE Auth Packet


 

Description 

Versa would like to issue this advisory for buffer overflow vulnerability in the IPsec implementation on VOS, aka Versa FlexVNF. When a maliciously crafted IKE Auth packet is sent to VOS, the vsmd process crashes, thereby resulting in a Denial of Service. An attacker can create a Denial-of-Service attack on the VOS appliances by crafting a malicious IKE Auth packet and sending it to the WAN interfaces on the VOS. 

During the IKE Authentication phase, if the IKE SA negotiation fails, and the size of the Remote ID is larger than the buffer size used to process the Remote ID, it will result in a crash of the vsmd process on the VOS appliance. 

VOS nodes configured with IPsec VPN profiles of type controller-staging-sdwan or remote-access-server using a WAN interface as the IPsec endpoint are vulnerable. (IPsec profiles configured with an overlay interface as the IPsec endpoint are not affected.) This configuration typically applies to all Controllers, Hub Controllers, and SSE Gateways. Additionally, site-to-site VPN profiles configured without a peer IP address, hostname, or FQDN are also vulnerable. 

The VOS nodes listed above are not vulnerable if they are not accessible from the Internet.

Severity 

CRITICAL 

Weakness Type 

CWE-121: Stack-based buffer overflow 

Exploitation Status 

Versa Networks is aware of the malicious IPsec packets originating from the following source IP blocks at this time.  

45.142.193.0/24, 102.135.43.0/24, 102.135.44.0/23, 102.135.46.0/24 

Product Status 

Version 

Affected 

Unaffected 

21.2.3

All versions are affected

EOS. Please upgrade to 22.1.4.

22.1.2

All version are affected.

July 26, 2026, or later. 
Software available now. 

22.1.3 

All versions are affected 

July 26, 2026, or later. 

22.1.4 

All versions are affected 

July 26, 2026, or later. 
Software available now. 

23.1.X 

All versions are affected 

Software will be made available by August 1, 2026.

Workarounds or Mitigation 

  • Export the Controller/Hub-Controller configuration for backup, and delete the staging VPN profile on Controllers or Hub Controllers when Zero-Touch Provisioning (ZTP) over the Internet is not actively required. Add the profile only for the duration of device bootstrapping. 
  • For site-to-site IPsec VPN profiles without a configured remote peer, specify the remote peer IP address, hostname, or fully qualified domain name (FQDN). 
  • If the source IP address associated with exploitation attempts is known, configure a discard or blackhole route for that IP address to block the malicious traffic. 

Permanent Resolution 

Upgrade to a software release that includes the fix for this vulnerability. After the upgrade is completed, the mitigations described above are no longer required. 

Software Download Links 

To download and install the Hotfix with the patch, log in to the Support portal, where you can view the release notes and access the download link. 

For 22.1.3 

https://support.versa-networks.com/support_home/en/release-22-1-3?sys_kb_id=7ac894ce2bde47101b07f5026e91bf1e&id=kb_article_view 

For 22.1.4: 

https://support.versa-networks.com/support_home/en/release-22-1-4?sys_kb_id=7b4b480a2bda47101b07f5026e91bfff&id=kb_article_view