Back to overview

CVE-2024-42448

CRITICAL
9.9
CVSS 3.0
Description
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

Metadata

CVE ID
CVE-2024-42448
State
PUBLISHED
Assigner
hackerone
Reserved
2024-08-02 01:04 UTC
Published
2024-12-11 18:52 UTC
Last updated
2024-12-12 14:42 UTC
Primary CWE
CWE-94
CWE-94 Improper Control of Generation of Code ('Code Injecti…
Vendor / Product
Veeam / Service Provider Console
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Veeam Service Provider Console 8.1 ≤ 8.1
Weakness (CWE)
CWESourceDescription
CWE-94 adp CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview