CVE-2024-39715
EUVD-2024-3820107.09.2024, 17:15
A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| veeam | service_provider_console | 8.0.0.19552 ≤ 𝑥 ≤ 8.0.0.19552 |
𝑥
= Vulnerable software versions
References