Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5h2f-vwh5-pc3g

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

EPSS

Процентиль: 96%
0.29663
Средний

9.9 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.9
nvd
больше 1 года назад

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

EPSS

Процентиль: 96%
0.29663
Средний

9.9 Critical

CVSS3

Дефекты

CWE-502