A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
References
History

Mon, 09 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Veeam
Veeam one
Weaknesses CWE-250
CPEs cpe:2.3:a:veeam:one:*:*:*:*:*:*:*:*
Vendors & Products Veeam
Veeam one
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 07 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
References
Metrics cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2024-09-07T16:11:22.220Z

Updated: 2024-09-09T14:11:39.524Z

Reserved: 2024-07-27T01:04:08.013Z

Link: CVE-2024-42024

cve-icon Vulnrichment

Updated: 2024-09-09T14:09:25.538Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-07T17:15:14.700

Modified: 2024-09-09T14:35:06.053

Link: CVE-2024-42024

cve-icon Redhat

No data.