Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39888 | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.veeam.com/kb4693 |
|
Fri, 25 Apr 2025 02:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veeam
Veeam veeam Backup \& Replication |
|
| CPEs | cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Veeam
Veeam veeam Backup \& Replication |
|
| Metrics |
cvssV3_1
|
Thu, 05 Dec 2024 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
ssvc
|
Wed, 04 Dec 2024 10:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services. | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-12-04T14:54:37.763Z
Reserved: 2024-08-02T01:04:07.985Z
Link: CVE-2024-42453
Updated: 2024-12-04T14:54:34.464Z
Status : Analyzed
Published: 2024-12-04T02:15:04.837
Modified: 2025-04-24T17:11:34.860
Link: CVE-2024-42453
No data.
OpenCVE Enrichment
No data.
EUVD