PT-2024-5947 · Veeam · Veeam Service Provider Console

Published

2024-09-04

·

Updated

2024-10-19

·

CVE-2024-39714

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veeam Service Provider Console (VSPC) (affected versions not specified)
Description The issue is related to a code injection vulnerability that allows a low-privileged user to upload arbitrary files to the server, leading to remote code execution on the VSPC server. This vulnerability is associated with an unlimited upload of dangerous file types. Exploitation of this issue may enable a remote attacker to execute arbitrary code on the VSPC server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-06754
CVE-2024-39714

Affected Products

Veeam Service Provider Console