CVE-2024-42021

medium Veeam
CVSS v3 Base Score
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: September 7, 2024 (614 days ago)
Last Modified: April 28, 2025
Vendor: Veeam
Source: NVD

Description

An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

References