nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45206 CVE-2024-45206
MEDIUM
Record summary
CVE-2024-45206 has a selected CVSS score of 6.5 (medium).
Description
A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Service Provider ConsoleBrowse Veeam / Service Provider ConsoleDefault status: unaffected, unknown | CVE List | 8.0 to ≤ 8.0 | affected |
| 8.0 to ≤ 8.0.0.19552 | affected |
References
2veeam.com
https://www.veeam.com/kb4649