First published: Sat Sep 07 2024(Updated: )
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam ONE | >=12.0.0.2498<12.2.0.4093 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-42022 is classified as a medium risk due to incorrect permission assignments.
To fix CVE-2024-42022, update Veeam ONE to version 12.2.0.4094 or later.
CVE-2024-42022 affects Veeam ONE versions 12.0.0.2498 to 12.2.0.4093.
An attacker can modify product configuration files due to incorrect permission assignments in CVE-2024-42022.
A temporary workaround for CVE-2024-42022 involves reviewing and restricting permissions on configuration files until the software is updated.