Record summary

CVE-2024-42448 has a selected CVSS score of 9.9 (critical); EIP currently links 1 repository PoC. VulnCheck reports CVE-2024-42448 use in known ransomware campaigns.

Description

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 23, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List8.1 to ≤ 8.1affected

Veeam Service Provider Console

Browse Veeam / Veeam Service Provider Console
VulnCheckVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubh3lye/CVE-2024-42448-RCERepository PoCby h3lyeStars: 0Not analyzed1 file

966 B

GitHub

PoC details

References

2