Multiple Vulnerabilities in Veeam Products Could Allow for Remote Code Execution
ID: 0e5b34e9-8042-5ce1-91f0-b6a85732fd3d
STIX ID: report--0e5b34e9-8042-5ce1-91f0-b6a85732fd3d
Feed Name: CISecurity.org Advisories
Multiple critical and high-severity vulnerabilities were identified in Veeam products (Backup & Replication, VSPC, and Veeam ONE). Notable issues include an unauthenticated remote code execution (CVE-2024-40711), RCE and credential extraction via a low-privileged role (CVE-2024-40710), RCE with Veeam ONE Agent credentials (CVE-2024-42024), and several additional CVEs enabling remote code execution, privilege escalation, arbitrary file upload/overwrite, MFA bypass, and credential exposure; successful exploitation could allow attackers to execute code, escalate privileges, and access or modify sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
