2024-12-08 03:06:42 +00:00

60 lines
2.6 KiB
JSON

{
"id": "CVE-2024-42456",
"sourceIdentifier": "support@hackerone.com",
"published": "2024-12-04T02:15:05.033",
"lastModified": "2024-12-04T17:15:14.233",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result in unauthorized access, enabling the user to call privileged methods and initiate critical services. The issue arises due to insufficient permission requirements on the method, allowing users with low privileges to perform actions that should require higher-level permissions."
},
{
"lang": "es",
"value": "Una vulnerabilidad en la plataforma Veeam Backup & Replication permite que un usuario con pocos privilegios y un rol espec\u00edfico aproveche un m\u00e9todo que actualiza ajustes de configuraci\u00f3n cr\u00edticos, como modificar el certificado de cliente de confianza utilizado para la autenticaci\u00f3n en un puerto espec\u00edfico. Esto puede generar un acceso no autorizado, lo que permite al usuario llamar a m\u00e9todos privilegiados e iniciar servicios cr\u00edticos. El problema surge debido a que no se cumplen los requisitos de permisos suficientes en el m\u00e9todo, lo que permite que los usuarios con pocos privilegios realicen acciones que deber\u00edan requerir permisos de nivel superior."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "support@hackerone.com",
"type": "Secondary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"references": [
{
"url": "https://www.veeam.com/kb4693",
"source": "support@hackerone.com"
}
]
}