Veeam Security Update – 09 May 2024

Veeam has released a security update to fix a vulnerability in Veeam Service Provider Console versions (4.0, 5.0, 6.0, 7.0, 8.0).

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system.

Veeam Service Provider Console (VSPC) Remote Code Execution Vulnerability (CVE-2024-29212):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-29212

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Veeam Security Update

References