A vulnerability in Veeam Service Provider Console allows for remote code execution.
Severity: Critical
CVSS v3.1 Score: 9.4CVSS:AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: Reported by putsi through HackerOne.
This vulnerability was fixed starting with the following build:
This vulnerability is related to script execution within alarms, which is disabled by default in v9.2 unless the VSPC instance already has alarms configured with a script execution action. If no such alarms exist, the vulnerability is not applicable.
To check whether an instance is affected:
C:\ProgramData\Veeam\Veeam Availability Console\Configuration\Service\configuration.overrides.json
configuration.overrides.json file, review the value of:
"AlarmManagement_ScriptExecutionEnabled"
False, then the deployment is not affected.True, the issue can be mitigated prior to applying v9.2.1, by setting the value to "False" and restarting the Veeam Management Portal Service.If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case