On May 28th, 2024, Veeam issued an enhanced update to address this critical vulnerability in Veeam Service Provider Console (VSPC). Although our initial patch, issued on May 7th, effectively addressed the primary concern, a subsequent review identified an area for further improvement. To ensure comprehensive protection, we swiftly developed and released a refined patch that fully mitigates the issue. We're confident this updated version reinforces the security of VSPC and demonstrates our commitment to continually strengthening our response measures.
Please review the Solution section closely and ensure that your Veeam Service Provider Console deployment is updated.
This article documents a vulnerability discovered in Veeam Service Provider Console.
This vulnerability does not affect other Veeam products (e.g., Veeam Backup & Replication, Veeam Agent for Microsoft Windows, Veeam ONE).
Due to an unsafe deserialization method used by the Veeam Service Provider Console (VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.
This vulnerability was detected during internal testing.
Severity: Critical
CVSS v3.1 Score: 9.9CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case