← Back to browse · API

CVE-2024-29212

Severity
CRITICAL
CVSS
9.9
EPSS
0.01551
Risk score
40.14
CISA KEV
No
PoC
No
Published
2024-05-13
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-26229, GHSA-5H2F-VWH5-PC3G
Products
Veeam:Service Provider Console 7 ≤7, Veeam:Service Provider Console 8 ≤8
Sources
euvd EUVD-2024-26229

Description

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

References