CVE-2018-16497: Versa-Networks Versa Analytics
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, the job runs a script as root that is writable by users who are members of the versa group.
Affected products
- Versa-Networks Versa Analytics: before 16.1R2S11 (fixed in 16.1R2S11); from 20.2.0, before 20.2.2 (fixed in 20.2.2); from 21.1.0, before 21.1.1 (fixed in 21.1.1); from 21.2.0, before 21.2.1 (fixed in 21.2.1)
Published 2021-05-26. Last modified 2026-08-31.