Veeam: community verdicts
4 notable / known-exploited Veeam CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Veeam CVE, see NVD ↗.
- CVE-2024-40711CRIT 9.8KEVEPSS 90%
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
- CVE-2023-27532HIGH 7.5KEVEPSS 78%
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
- CVE-2022-26500HIGH 8.8KEVEPSS 6%
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
- CVE-2022-26501CRIT 9.8KEVEPSS 4%
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).