A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
References
Link | Resource |
---|---|
https://www.veeam.com/kb4649 | Vendor Advisory |
Configurations
History
28 Apr 2025, 16:47
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:veeam:one:*:*:*:*:*:*:*:* | |
First Time |
Veeam
Veeam one |
|
References | () https://www.veeam.com/kb4649 - Vendor Advisory |
09 Sep 2024, 14:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-250 |
09 Sep 2024, 13:03
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Sep 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-07 17:15
Updated : 2025-04-28 16:47
NVD link : CVE-2024-42024
Mitre link : CVE-2024-42024
CVE.ORG link : CVE-2024-42024
JSON object : View
Products Affected
veeam
- one
CWE
CWE-250
Execution with Unnecessary Privileges