ZeroHour

CVE-2024-29212

CVSS 3.0
9.9 critical
EPSS
2%p74
Published
()
Modified
Description

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

Vendors
veeam
Products
veeam service provider console
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news