Information disclosure in Veeam Service Provider Console - CVE-2024-42449

 

Information disclosure in Veeam Service Provider Console - CVE-2024-42449

Published: December 3, 2024


Vulnerability identifier: #VU101170
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42449
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to excessive data output by the application. A remote authenticated user can leak an NTLM hash of the VSPC server service account and delete files on the VSPC server machine.


Affected software

Veeam Service Provider Console

How to mitigate CVE-2024-42449

Install updates from vendor's website.

Veeam Service Provider Console - update to 8.1.0.21999

External References

Related Security Bulletins