CVE-2024-42453
- EPSS 0.1%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:11:34
A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configur...
CVE-2024-42451
- EPSS 0.09%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:20:53
A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious s...
CVE-2024-40717
- EPSS 3.13%
- Veröffentlicht 04.12.2024 02:15:04
- Zuletzt bearbeitet 24.04.2025 17:21:39
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a netwo...
CVE-2024-40715
- EPSS 0.22%
- Veröffentlicht 07.11.2024 17:15:08
- Zuletzt bearbeitet 11.07.2025 13:57:02
A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.
CVE-2024-40714
- EPSS 0.35%
- Veröffentlicht 07.09.2024 17:15:13
- Zuletzt bearbeitet 01.05.2025 18:17:19
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
CVE-2024-40713
- EPSS 0.02%
- Veröffentlicht 07.09.2024 17:15:13
- Zuletzt bearbeitet 01.05.2025 18:17:17
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
CVE-2024-40712
- EPSS 0.26%
- Veröffentlicht 07.09.2024 17:15:13
- Zuletzt bearbeitet 01.05.2025 18:17:14
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
CVE-2024-40710
- EPSS 4.2%
- Veröffentlicht 07.09.2024 17:15:13
- Zuletzt bearbeitet 01.05.2025 18:13:16
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user...
CVE-2024-29852
- EPSS 0.32%
- Veröffentlicht 22.05.2024 23:15:09
- Zuletzt bearbeitet 03.07.2025 15:48:06
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
CVE-2024-29851
- EPSS 0.4%
- Veröffentlicht 22.05.2024 23:15:09
- Zuletzt bearbeitet 03.07.2025 16:11:32
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.