Loading HuntDB...

Version 12.1.2

SEMANTIC 7 CVEs

Known Vulnerabilities

CVE-2024-40714

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

HIGH CVSS 8.3 Published Sep 07, 2024

CVE-2024-40713

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

HIGH CVSS 7.8 Published Sep 07, 2024

CVE-2024-40709

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

HIGH CVSS 7.8 Published Sep 07, 2024

CVE-2024-40711

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

CRITICAL CVSS 9.8 Published Sep 07, 2024

CVE-2024-40712

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

HIGH CVSS 7.8 Published Sep 07, 2024

CVE-2024-40710

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.

HIGH CVSS 8.8 Published Sep 07, 2024

CVE-2024-39718

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

HIGH CVSS 8.1 Published Sep 07, 2024