PT-2024-5947 · Veeam · Veeam Service Provider Console

CVE-2024-39714

·

Published

2024-09-04

·

Updated

2024-10-19

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veeam Service Provider Console (VSPC) (affected versions not specified)
Description The issue is related to a code injection vulnerability that allows a low-privileged user to upload arbitrary files to the server, leading to remote code execution on the VSPC server. This vulnerability is associated with an unlimited upload of dangerous file types. Exploitation of this issue may enable a remote attacker to execute arbitrary code on the VSPC server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06754
CVE-2024-39714

Affected Products

Veeam Service Provider Console