Impact
A flaw in the Veeam Service Provider Console permits an unauthenticated user to intentionally exhaust host memory, ultimately stopping legitimate services from running. The weakness is a classic instance of CWE‑789, where insufficient resource checks allow service degradation for all users of the affected host.
Affected Systems
The vulnerability affects the Veeam Service Provider Console. No specific versions were disclosed, so the entire product line should be considered potentially vulnerable until a patch is found.
Risk and Exploitability
The remote attacker can trigger the memory exhaustion without needing credentials, resulting in a high‑impact denial of service with a CVSS score of 8.7. EPSS is not provided, and the vulnerability is not listed in the CISA KEV catalog, but the lack of mitigation guidance makes it a high priority for patching.
OpenCVE Enrichment