Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-78w4-wf5r-hgxq

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services.

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services.

EPSS

Процентиль: 28%
0.00102
Низкий

7.4 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 года назад

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services.

CVSS3: 7.4
fstec
больше 1 года назад

Уязвимость службы управления Veeam Backup Enterprise Manager средства защиты облачных, виртуальных и физических систем Veeam Backup & Replication, позволяющая нарушителю повысить свои привилегии и вызвать отказ в обслуживании

EPSS

Процентиль: 28%
0.00102
Низкий

7.4 High

CVSS3

Дефекты

CWE-862