Impact
A flaw in Veeam Service Provider Console permits an attacker who is not authenticated to reach the proxied appliance API with administrator rights for a very small time window that exists immediately after a legitimate administrator logs in. This allows the attacker to answer API calls as a Portal Administrator without performing any credential-based authentication. The vulnerability is an instance of Improper Authentication (CWE‑306).
Affected Systems
The affected product is Veeam Service Provider Console. No specific version information was provided; the issue applies to all releases of this console that are vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The exploit requires timing, as the attacker must act during a brief window after an administrator session begins. The likely attack vector is via network access to the proxied appliance API endpoint, potentially from an external source if that endpoint is exposed. Once exploited, the attacker gains full administrative privileges to the appliance through the API, enabling wide-ranging destructive or exfiltration capabilities.
OpenCVE Enrichment