PT-2024-9161 · Veeam · Veeam Service Provider Console

Published

2024-12-03

·

Updated

2024-12-10

·

CVE-2024-42449

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: Veeam Service Provider Console (VSPC) versions prior to 8.1.0.21377
Description: The issue is related to access control errors in the Veeam Service Provider Console (VSPC) backup and restore software for remote and cloud clients. It allows a remote attacker to delete arbitrary files on the VSPC server machine, provided that the management agent is authorized on the server. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: For versions prior to 8.1.0.21377, update to version 8.1.0.21377 or later to resolve the issue. As a temporary workaround, consider restricting access to the management agent to minimize the risk of exploitation.

Fix

Improper Access Control

Information Disclosure

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2024-10848
CVE-2024-42449

Affected Products

Veeam Service Provider Console