Show filters
63 Total Results
Displaying 31-40 of 63
Sort by:
Attacker Value
Unknown
CVE-2024-40713
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
0
Attacker Value
Unknown
CVE-2024-40712
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
0
Attacker Value
Unknown
CVE-2024-40710
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
0
Attacker Value
Unknown
CVE-2024-40709
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.
0
Attacker Value
Unknown
CVE-2024-39718
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
0
Attacker Value
Unknown
CVE-2024-39715
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.
0
Attacker Value
Unknown
CVE-2024-39714
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
0
Attacker Value
Unknown
CVE-2024-38651
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.
0
Attacker Value
Unknown
CVE-2024-38650
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.
0
Attacker Value
Unknown
CVE-2024-29855
Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
0