CVE-2024-45206

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.
References
Link Resource
https://www.veeam.com/kb4649 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:veeam:veeam_service_provider_console:*:*:*:*:*:*:*:*

History

02 Jul 2025, 20:34

Type Values Removed Values Added
CPE cpe:2.3:a:veeam:veeam_service_provider_console:*:*:*:*:*:*:*:*
References () https://www.veeam.com/kb4649 - () https://www.veeam.com/kb4649 - Vendor Advisory
First Time Veeam
Veeam veeam Service Provider Console

13 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-918

04 Dec 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-04 02:15

Updated : 2025-07-02 20:34


NVD link : CVE-2024-45206

Mitre link : CVE-2024-45206

CVE.ORG link : CVE-2024-45206


JSON object : View

Products Affected

veeam

  • veeam_service_provider_console
CWE
CWE-918

Server-Side Request Forgery (SSRF)