Chinese state-backed cyber attackers have been exploiting a zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717.
Discovered by Black Lotus Labs at Lumen Technologies, this vulnerability has been under active exploitation since June 2024, affecting various U.S. and global entities, particularly in the Internet service provider (ISP), managed service provider (MSP), and IT sectors.
The flaw exists within Versa’s software-defined wide area network (SD-WAN) applications, specifically impacting all versions of Versa Director released before version 22.1.4.
Versa Director servers play a crucial role in managing network configurations and orchestrating SD-WAN operations, making them prime targets for advanced persistent threat (APT) groups seeking control over large-scale network infrastructures.
With moderate confidence, the attacks have been linked to Chinese groups Volt Typhoon and Bronze Silhouette, who deployed a customized web shell known as “VersaMem.”

This advanced tool intercepts and captures credentials, allowing unauthorized access to downstream customer networks. The web shell’s modular design enables threat actors to inject additional Java code that operates exclusively in-memory, significantly reducing detection risk.
The attack chain begins when the attackers gain administrative access through an exposed Versa management port, designed for high-availability (HA) pairing of Director nodes, according to Black Lotus Labs.
After gaining access, the attackers deploy the VersaMem web shell, which integrates with the main Apache Tomcat process. It leverages the Java Instrumentation API and Javassist toolkit to dynamically modify Java code in-memory.
Key Capabilities of the VersaMem Web Shell include:
- Credential Interception: It hooks into Versa’s authentication processes to capture plaintext credentials, encrypting them with AES, and storing them on disk.
- In-Memory Code Execution: It integrates with the Tomcat application filter chain to load and execute Java modules directly in-memory, evading traditional file-based detection.
The exploitation campaign has been ongoing, with initial activity dating back to June 12, 2024. Black Lotus Labs detected unusual traffic patterns and compromised small-office/home-office (SOHO) devices involved in the attacks. The attackers exploited management port 4566, typically used for node pairing, to establish unauthorized connections.
Due to the critical nature of this vulnerability and the pivotal role of Versa Director in network management, Black Lotus Labs strongly recommends organizations upgrade to Versa Director version 22.1.4 or later.
Affected Systems and Versions:
- 22.1.4: None
- 22.1.3: Images released before the June 21, 2024, hotfix are affected. The June 21, 2024, Hot Fix and later versions are unaffected.
- 22.1.2: Images released before the June 21, 2024, hotfix are affected. The June 21, 2024, Hot Fix and later versions are unaffected.
- 22.1.1: All versions are affected. Upgrading to 22.1.3 or later is recommended.
- 21.2.3: Images released before the June 21, 2024, hotfix are affected. The June 21, 2024, and later versions are unaffected.
- 21.2.2: All versions are affected. Upgrading to 21.2.3 or later is recommended.
They also recommend implementing firewall rules to limit access to management ports and following Versa Networks’ security advisories for additional mitigation steps.
The Cybersecurity and Infrastructure Security Agency (CISA) strongly urges all organizations to promptly apply necessary software updates and actively monitor for any unauthorized or malicious activities within their network environments.



