CVE-2024-42453
Last modified
CVE-2024-42453 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Veeam | Veeam Backup \& Replication | >= 12.0.0.1402, < 12.3.0.310 |
References
- https://www.veeam.com/kb4693Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-42453?
How severe is CVE-2024-42453?
How do I fix CVE-2024-42453?
Are you affected by CVE-2024-42453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
