CVE-2024-29212
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.9epss 1.6%
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
nono source reports it
In short
Veeam Service Provider Console has a critical flaw in how it processes data from its management components, allowing attackers to run malicious code directly on the server machine.
Technical detail
The vulnerability stems from unsafe deserialization (CWE-502) in VSPC server's inter-component communication protocol. Under specific conditions, an attacker with network access to the management agent channel can inject malicious serialized objects, leading to unauthenticated Remote Code Execution with server-level privileges.
Summary generated and translated by AI from the official description.
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Veeam · Service Provider ConsoleReferences
https://www.veeam.com/kb4575