CVE-2024-42448
CRITICAL
9.9
CVSS 3.0
Description
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
Metadata
Severity & Metrics
9.9
CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Veeam | Service Provider Console | — | 8.1 ≤ 8.1 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-94 | adp | CWE-94 Improper Control of Generation of Code ('Code Injection') |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.9 | CRITICAL | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
References (1)