PT-2024-6327 · Veeam · Veeam Service Provider Console

Published

2024-09-04

·

Updated

2024-10-19

·

CVE-2024-39715

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veeam Service Provider Console (VSPC) (affected versions not specified)
Description A code injection vulnerability allows a low-privileged user with REST API access to remotely upload arbitrary files to the VSPC server, leading to remote code execution on the VSPC server. This issue is related to incorrect management of code generation in the implementation of the application programming interface for the Veeam Service Provider Console (VSPC) software for remote and cloud clients.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07278
CVE-2024-39715

Affected Products

Veeam Service Provider Console