CVE-2024-45206: Veeam Service Provider Console

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get information about internal resources.

Affected products

  • Veeam Veeam Service Provider Console: from 7.0.0.12777, before 8.1.0.21377 (fixed in 8.1.0.21377)

Published 2024-12-04. Last modified 2026-06-17.