A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.veeam.com/kb4649 |
![]() ![]() |
History
Wed, 02 Jul 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Veeam veeam Service Provider Console
|
|
CPEs | cpe:2.3:a:veeam:veeam_service_provider_console:*:*:*:*:*:*:*:* | |
Vendors & Products |
Veeam veeam Service Provider Console
|
Thu, 13 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-918 |
Wed, 04 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Veeam
Veeam service Provider Console |
|
CPEs | cpe:2.3:a:veeam:service_provider_console:*:*:*:*:*:*:*:* | |
Vendors & Products |
Veeam
Veeam service Provider Console |
|
Metrics |
ssvc
|
Wed, 04 Dec 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources. | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-03-13T18:36:04.573Z
Reserved: 2024-08-23T01:00:01.061Z
Link: CVE-2024-45206

Updated: 2024-12-04T16:05:52.552Z

Status : Analyzed
Published: 2024-12-04T02:15:05.427
Modified: 2025-07-02T20:34:43.323
Link: CVE-2024-45206

No data.