Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown
CVE-2024-42449
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.
0
Attacker Value
Unknown
CVE-2024-40717
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.
0
Attacker Value
Unknown
CVE-2024-42024
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
0
Attacker Value
Unknown
CVE-2024-42023
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
0
Attacker Value
Unknown
CVE-2024-42022
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
0
Attacker Value
Unknown
CVE-2024-42021
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
0
Attacker Value
Unknown
CVE-2024-42020
Disclosure Date: September 07, 2024 (last updated October 17, 2024)
A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
0
Attacker Value
Unknown
CVE-2024-42019
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.
0
Attacker Value
Unknown
CVE-2024-40718
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
0
Attacker Value
Unknown
CVE-2024-40714
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
0