target entity

Veeam

4 source-linked records in the current knowledge graph.

high

CVE-2024-40711: Veeam Backup and Replication Deserialization Vulnerability

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-40711EPSS 90.2%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2023-27532: Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-27532EPSS 77.6%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26500: Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. Required action: Apply updates per vendor instructions.

CVE-2022-26500EPSS 5.9%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26501: Veeam Backup & Replication Remote Code Execution Vulnerability

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code. Required action: Apply updates per vendor instructions.

CVE-2022-26501EPSS 4.3%Backup & ReplicationVeeam
CISA KEV ↗ · unattributed attribution