CVE-2025-48983
- EPSS 0.24%
- Veröffentlicht 30.10.2025 23:33:01
- Zuletzt bearbeitet 01.12.2025 21:15:50
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
CVE-2025-48984
- EPSS 0.3%
- Veröffentlicht 30.10.2025 23:31:34
- Zuletzt bearbeitet 11.11.2025 02:08:57
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2024-42456
- EPSS 0.07%
- Veröffentlicht 04.12.2024 02:15:05
- Zuletzt bearbeitet 24.04.2025 17:09:48
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a s...
CVE-2024-42457
- EPSS 0.09%
- Veröffentlicht 04.12.2024 02:15:05
- Zuletzt bearbeitet 24.04.2025 17:08:34
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for cr...
CVE-2024-45204
- EPSS 0.07%
- Veröffentlicht 04.12.2024 02:15:05
- Zuletzt bearbeitet 24.04.2025 16:59:33
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting ...
CVE-2024-40717
- EPSS 0.53%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:21:39
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a netwo...
CVE-2024-42451
- EPSS 0.06%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:20:53
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious s...
CVE-2024-42452
- EPSS 0.14%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:20:29
A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the ser...
CVE-2024-42453
- EPSS 0.1%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:11:34
A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configur...
CVE-2024-42455
- EPSS 0.13%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:10:10
A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on ...