Vulnerabilities
Vulnerable Software
Veeam:  Security Vulnerabilities
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
CVSS Score
7.5
EPSS Score
0.001
Published
2024-09-07
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
CVSS Score
7.8
EPSS Score
0.003
Published
2024-09-07
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
CVSS Score
9.1
EPSS Score
0.024
Published
2024-09-07
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
CVSS Score
8.8
EPSS Score
0.088
Published
2024-09-07
CVE-2024-40711
Known exploited
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
CVSS Score
9.8
EPSS Score
0.744
Published
2024-09-07
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
CVSS Score
7.8
EPSS Score
0.003
Published
2024-09-07
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
CVSS Score
7.8
EPSS Score
0.0
Published
2024-09-07
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
CVSS Score
8.3
EPSS Score
0.004
Published
2024-09-07
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.
CVSS Score
9.0
EPSS Score
0.004
Published
2024-09-07
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
CVSS Score
8.1
EPSS Score
0.005
Published
2024-09-07


Contact Us

Shodan ® - All rights reserved