PT-2024-22813 · Veeam · Veeam Service Provider Console
Published
2024-05-08
·
Updated
2025-06-30
·
CVE-2024-29212
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veeam Service Provider Console versions 4.0 through 8.0
Description
The issue is due to an unsafe de-serialization method used by the Veeam Service Provider Console server in communication between the management agent and its components. This allows for Remote Code Execution (RCE) on the VSPC server machine under certain conditions. The estimated number of potentially affected devices worldwide is over 9,000. There is a risk of system compromise and data leakage. No exploits have been reported yet.
Recommendations
For versions 4.0 through 8.0, patch the systems as soon as possible to resolve the issue. As a temporary workaround, consider restricting access to the management agent and its components to minimize the risk of exploitation. Avoid using any potentially vulnerable functions or parameters in the affected API endpoints until the issue is resolved.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veeam Service Provider Console