← back
CVE-2024-29212criticalCWE-502

CVE-2024-29212

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.9epss 1.6%
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
nono source reports it
In short

Veeam Service Provider Console has a critical flaw in how it processes data from its management components, allowing attackers to run malicious code directly on the server machine.

Technical detail

The vulnerability stems from unsafe deserialization (CWE-502) in VSPC server's inter-component communication protocol. Under specific conditions, an attacker with network access to the management agent channel can inject malicious serialized objects, leading to unauthenticated Remote Code Execution with server-level privileges.

Summary generated and translated by AI from the official description.
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H