Back to overview

CVE-2024-29212

CRITICAL
9.9
CVSS 3.0
Description
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

Metadata

CVE ID
CVE-2024-29212
State
PUBLISHED
Assigner
hackerone
Reserved
2024-03-19 01:04 UTC
Published
2024-05-13 01:07 UTC
Last updated
2024-08-02 01:10 UTC
Primary CWE
CWE-502
CWE-502 Deserialization of Untrusted Data
Vendor / Product
Veeam / Service Provider Console
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Veeam Service Provider Console 8 ≤ 8, 7 ≤ 7
Weakness (CWE)
CWESourceDescription
CWE-502 adp CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview