Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
High
CVE-2023-27532
Disclosure Date: March 10, 2023 (last updated May 10, 2024)
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
11
Attacker Value
Very High
CVE-2024-40711
Disclosure Date: September 07, 2024 (last updated October 19, 2024)
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
2
Attacker Value
Unknown
CVE-2024-39715
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.
0
Attacker Value
Unknown
CVE-2024-39714
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
0
Attacker Value
Unknown
CVE-2024-38651
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.
0
Attacker Value
Unknown
CVE-2024-38650
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
0
Attacker Value
Unknown
CVE-2022-43549
Disclosure Date: December 05, 2022 (last updated October 08, 2023)
Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.
0
Attacker Value
Unknown
CVE-2022-26504
Disclosure Date: March 17, 2022 (last updated May 10, 2024)
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe
0
Attacker Value
Unknown
CVE-2022-26501
Disclosure Date: March 17, 2022 (last updated May 10, 2024)
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2022-26500
Disclosure Date: March 17, 2022 (last updated May 10, 2024)
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
0