PT-2024-9040 · Veeam · Veeam Service Provider Console
Published
2024-12-03
·
Updated
2024-12-15
·
CVE-2024-42448
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Veeam Service Provider Console versions prior to 8.1.0.21999
Description:
The issue is related to a critical flaw in the Veeam Service Provider Console that could allow remote code execution. This flaw was discovered during internal testing and has a high severity score. From the VSPC management agent machine, under the condition that the management agent is authorized on the server, it is possible to perform remote code execution on the VSPC server machine. Over 143,000 services are potentially affected.
Recommendations:
Update Veeam Service Provider Console to version 8.1.0.21999 immediately to address the vulnerability.
As a temporary workaround, consider restricting access to the VSPC server machine to minimize the risk of unauthorized access until the update is applied.
Fix
Improper Privilege Management
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Veeam Service Provider Console