CVE-2024-42453: High severity veeam vulnerability
A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially leading to Denial of Service (DoS) and data integrity issues. The vulnerability is caused by improper permission checks in methods accessed via management services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42453?
CVE-2024-42453 is considered a high severity vulnerability due to its potential to allow low-privileged users to manipulate critical configurations.
How do I fix CVE-2024-42453?
To fix CVE-2024-42453, ensure that access controls are properly configured and restrict permissions for low-privileged users in Veeam Backup & Replication.
What systems are affected by CVE-2024-42453?
CVE-2024-42453 specifically affects Veeam Backup & Replication software.
What kind of actions can be performed by exploiting CVE-2024-42453?
Exploiting CVE-2024-42453 allows low-privileged users to power off virtual machines, delete storage files, and alter configurations.
Is there a patch available for CVE-2024-42453?
As of now, check the Veeam support site for updates or patches addressing CVE-2024-42453.