---
cve: "CVE-2024-42448"
severity: "CRITICAL"
cvss: 9.9
epss: "20.1%"
vendor: "Veeam"
kev: false
exploited: false
published: "2024-12-12 01:59:47"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T15:44:13+02:00"
---

# CVE-2024-42448

> 9.9 CRITICAL

## Beschreibung

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

## CVSS-Vektor

```
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.veeam.com/kb4679>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-42448) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
