Loading HuntDB...

Backup

1 Version 7 CVEs

Recent CVEs

CVE-2024-40714

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

HIGH Sep 07, 2024

CVE-2024-40713

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

HIGH Sep 07, 2024

CVE-2024-40709

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

HIGH Sep 07, 2024

CVE-2024-40711

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

CRITICAL Sep 07, 2024

CVE-2024-40712

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

HIGH Sep 07, 2024

CVE-2024-40710

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.

HIGH Sep 07, 2024

CVE-2024-39718

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

HIGH Sep 07, 2024