CVE-2024-42024
Estado: AnalizadaAlta (8.8)—
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.25%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-250
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-42024",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-42024",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-09T14:04:05.003945Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.3
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "Veeam",
"product": "One",
"versions": [
{
"status": "affected",
"version": "12.1",
"versionType": "semver",
"lessThanOrEqual": "12.1"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:veeam:one:*:*:*:*:*:*:*:*"
],
"vendor": "veeam",
"product": "one",
"versions": [
{
"status": "affected",
"version": "12",
"versionType": "semver",
"lessThanOrEqual": "12.1.0.3208"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-09-07T17:15:14.700",
"references": [
{
"url": "https://www.veeam.com/kb4649",
"tags": [
"Vendor Advisory"
],
"source": "support@hackerone.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-250"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed."
},
{
"lang": "es",
"value": "Una vulnerabilidad que permite a un atacante en posesión de las credenciales de la cuenta de servicio de Veeam ONE Agent realizar una ejecución remota de código en la máquina donde está instalado Veeam ONE Agent."
}
],
"lastModified": "2026-06-17T07:48:39.533",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:veeam:one:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4311B3C-EDCD-4BA9-9664-4BEF670BAC33",
"versionEndExcluding": "12.2.0.4093",
"versionStartIncluding": "12.0.0.2498"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}