Impact
The vulnerability in Veeam Service Provider Console permits an attacker to write arbitrary files to the management server. By doing so, the attacker can place executable or malicious code on the server, enabling remote code execution with the privileges of the Veeam process. The flaw is rooted in an improper handling of file paths, identified as CWE‑22, and directly leads to loss of confidentiality, integrity, and availability of the affected system.
Affected Systems
Veeam Service Provider Console is affected, but specific product versions are not disclosed in the available data. The general impact applies to any installation that has not applied a patch or upgrade that addresses this file‑write weakness.
Risk and Exploitability
The CVSS score of 9.0 signals a critical severity, and although EPSS data is unavailable, the lack of a KEV listing does not reduce the risk. The attack vector is likely through the console’s management interface, where an authenticated or unauthenticated attacker could supply a crafted file name/path. Once the file is written, the attacker could execute it on the management server, gaining full remote control.
OpenCVE Enrichment