Veeam Service Provider Console Vulnerability
( CVE-2024-29212 )
Article Applicability
This article documents a vulnerability discovered in Veeam Service Provider Console.
This does not affect any other Veeam product (e.g., Veeam Backup & Replication, Veeam Agent for Microsoft Windows, Veeam ONE)
Issue Details
CVE-2024-29212
Due to an unsafe deserialization method used by the Veeam Service Provider Console (VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
This vulnerability was detected during internal testing.
Severity: High
CVSS v3.1 Score: 8.8
Solution
The vulnerability documented in this article was fixed starting in the following builds of Veeam Service Provider Console:
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.