Show filters
63 Total Results
Displaying 21-30 of 63
Sort by:
Attacker Value
Unknown

CVE-2024-42449

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.
0
Attacker Value
Unknown

CVE-2024-40717

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed with elevated privileges by default. The user can update a job and schedule it to run almost immediately, allowing arbitrary code execution on the server.
0
Attacker Value
Unknown

CVE-2024-42024

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
0
Attacker Value
Unknown

CVE-2024-42023

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.
0
Attacker Value
Unknown

CVE-2024-42022

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
0
Attacker Value
Unknown

CVE-2024-42021

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
0
Attacker Value
Unknown

CVE-2024-42020

Disclosure Date: September 07, 2024 (last updated October 17, 2024)
A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.
Attacker Value
Unknown

CVE-2024-42019

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.
0
Attacker Value
Unknown

CVE-2024-40718

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
0
Attacker Value
Unknown

CVE-2024-40714

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
0