Impact
The vulnerability in Veeam Service Provider Console allows an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. This flaw, classified as CWE‑288 (Authentication Bypass), can result in an attacker being able to masquerade as a legitimate agent and gain access to sensitive credentials that may be used to control other components of the managed infrastructure. The compromised credentials can enable further lateral movement, data exfiltration, or administrative takeover of the target environment.
Affected Systems
The affected system is the Veeam Service Provider Console. No specific version information was provided, so all installations of the console are potentially vulnerable. Administrators should verify the product version and consult Veeam documentation for any additional guidance.
Risk and Exploitability
The CVSS score of 9.5 indicates a high severity vulnerability, with the EPSS score unavailable and the vulnerability not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated network connection to the console, as described in the advisory. If an attacker can reach the console, they can exploit the authentication bypass to impersonate an agent and obtain credentials, which could lead to full control of the managed environment. The risk is high, and the vulnerability is actively exploitable under the conditions described.
OpenCVE Enrichment