PT-2024-6327 · Veeam · Veeam Service Provider Console
Published
2024-09-04
·
Updated
2024-10-19
·
CVE-2024-39715
CVSS v3.1
8.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Veeam Service Provider Console (VSPC) (affected versions not specified)
Description
A code injection vulnerability allows a low-privileged user with REST API access to remotely upload arbitrary files to the VSPC server, leading to remote code execution on the VSPC server. This issue is related to incorrect management of code generation in the implementation of the application programming interface for the Veeam Service Provider Console (VSPC) software for remote and cloud clients.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veeam Service Provider Console