CVE-2025-34026
Versa Concerto Improper Authentication Vulnerability
⚠ KEVEPSS 71.1%
Description
Versa Concerto SD-WAN orchestration platform contains an improper authentication vulnerability in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.
How to fix CVE-2025-34026
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2025-34026 being exploited?
Yes — CVE-2025-34026 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.