This vulnerability in Veeam Service Provider Console allows for remote code execution.
The vulnerability classified as CWE-233 (Improper Handling of Parameters) allows an attacker to execute arbitrary code remotely on the vulnerable system. Network attack vector (AV:N) without requiring user interaction (UI:N) with low privilege requirements (PR:L) means that basic access to the console is sufficient to conduct a successful attack. The vulnerability affects both resources of the target system and related systems (SC:H/SI:H/SA:H).
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code remotely, which can lead to complete system takeover, data theft, and compromise of integrity and availability of both the target system and related systems.
Patches available from the vendor should be applied in accordance with references published at https://www.veeam.com/kb4853. Until patches are deployed, it is recommended to restrict network access to Veeam Service Provider Console exclusively to trusted hosts and monitor logs for unauthorized activities.
Veeam Service Provider Console — versions indicated in vendor references (https://www.veeam.com/kb4853)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X