Showing 10 vulnerabilities on this page for Service Provider Console

Signals CISA KEV Ransomware Nuclei
Veeam vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Veeam Service Provider Console Arbitrary File Write to Remote Code Execution

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

CWE-22Aug 4, 2026
CVSS9.0v4.0EPSS0.376%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Authentication Bypass via Impersonation

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

CWE-288Aug 4, 2026
CVSS9.5v4.0EPSS0.224%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Authentication Bypass via Proxied API

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.

CWE-306Aug 4, 2026
CVSS8.2v4.0EPSS0.281%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Memory Allocation Denial of Service

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

CWE-789Aug 4, 2026
CVSS8.7v4.0EPSS0.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Forgot Password ReturnUrl Open Redirect and Account Takeover

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.

CWE-640Jul 30, 2026
CVSS5.3v3.1EPSS0.19%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Veeam Service Provider Console Remote Code Execution Vulnerability

This vulnerability in Veeam Service Provider Console allows for remote code execution.

CWE-233May 28, 2026
CVSS9.4v4.0EPSS0.403%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Veeam Service Provider Console Remote Code Execution Vulnerability

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

CWE-94Dec 11, 2024
CVSS9.9v3.0EPSS20.1%PoCs1SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

CWE-918Dec 4, 2024
CVSS6.5v3.0EPSS0.242%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.

CWE-732Dec 4, 2024
CVSS7.1v3.0EPSS5.81%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

CWE-502May 13, 2024
CVSS9.9v3.0EPSS1.55%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX