Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2024-40714
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
0
Attacker Value
Unknown
CVE-2024-40713
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
0
Attacker Value
Unknown
CVE-2024-40712
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
0
Attacker Value
Unknown
CVE-2024-40710
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
0
Attacker Value
Unknown
CVE-2024-40709
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.
0
Attacker Value
Unknown
CVE-2024-39718
Disclosure Date: September 07, 2024 (last updated September 08, 2024)
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
0
Attacker Value
Unknown
CVE-2024-22903
Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
0
Attacker Value
Unknown
CVE-2024-22902
Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
0
Attacker Value
Unknown
CVE-2024-22901
Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
0
Attacker Value
Unknown
CVE-2024-22900
Disclosure Date: February 02, 2024 (last updated February 08, 2024)
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
0