CVE-2018-16495: Versa-Networks Versa Operating System
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.
Affected products
- Versa-Networks Versa Operating System: before 16.1r2s11 (fixed in 16.1r2s11); from 20.2.0, before 20.2.2 (fixed in 20.2.2); from 21.1.0, before 21.1.1 (fixed in 21.1.1)
Published 2021-05-26. Last modified 2026-06-17.