Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2024-40714

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
0
Attacker Value
Unknown

CVE-2024-40713

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
0
Attacker Value
Unknown

CVE-2024-40712

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
0
Attacker Value
Unknown

CVE-2024-40710

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
0
Attacker Value
Unknown

CVE-2024-40709

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.
0
Attacker Value
Unknown

CVE-2024-39718

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
0
Attacker Value
Unknown

CVE-2024-22903

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
Attacker Value
Unknown

CVE-2024-22902

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Attacker Value
Unknown

CVE-2024-22901

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Attacker Value
Unknown

CVE-2024-22900

Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.