logo

Multiple Vulnerabilities in Veeam Products Could Allow for Remote Code Execution

ID: 0e5b34e9-8042-5ce1-91f0-b6a85732fd3d

STIX ID: report--0e5b34e9-8042-5ce1-91f0-b6a85732fd3d

Feed Name: CISecurity.org Advisories

Threat Score
78/100

Date Published: 2024-09-25

Date Updated: 2026-04-27

...
...

Multiple critical and high-severity vulnerabilities were identified in Veeam products (Backup & Replication, VSPC, and Veeam ONE). Notable issues include an unauthenticated remote code execution (CVE-2024-40711), RCE and credential extraction via a low-privileged role (CVE-2024-40710), RCE with Veeam ONE Agent credentials (CVE-2024-42024), and several additional CVEs enabling remote code execution, privilege escalation, arbitrary file upload/overwrite, MFA bypass, and credential exposure; successful exploitation could allow attackers to execute code, escalate privileges, and access or modify sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.