Vulnerability index

Browse CVEs

64 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

One MEDIUM 5.4
CVE-2024-42020

A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.

Fix: after 12.1.0.3208
Fix from $1,600 2024-09-07
One MEDIUM 5.3
CVE-2024-42022

An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.

Fix: 12.2.0.4093+
Fix from $1,600 2024-09-07
Veeam Backup \& Replication CRITICAL 9.8
CVE-2024-40711 KEVEPSS 90%

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Fix: 12.2.0.334+
Fix from $2,300 2024-09-07
Veeam Backup \& Replication HIGH 8.8
CVE-2024-40710

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sen…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Veeam Backup \& Replication HIGH 8.3
CVE-2024-40714

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credenti…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
One HIGH 8.0
CVE-2024-42019

A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction …

Fix: 12.2.0.4093+
Fix from $1,950 2024-09-07
Veeam Backup \& Replication HIGH 7.8
CVE-2024-40712

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation …

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Veeam Backup \& Replication HIGH 7.8
CVE-2024-40713

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Veeam Backup \& Replication HIGH 8.1
CVE-2024-39718

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to th…

Fix: 12.2.0.334+
Fix from $1,950 2024-09-07
Recovery Orchestrator CRITICAL 9.0
CVE-2024-29855EPSS 22%

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

Fix: 7.0.0.379 / 7.1.0.230+
Fix from $2,300 2024-06-11
Veeam Agent For Windows HIGH 7.8
CVE-2024-29853

An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.

Fix: 6.1.2.134+
Fix from $1,950 2024-05-22
Veeam Backup \& Replication HIGH 7.2
CVE-2024-29851

Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.

Fix: 12.1.2.172+
Fix from $1,950 2024-05-22
Veeam Backup \& Replication CRITICAL 9.8
CVE-2024-29849EPSS 17%

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

Fix: 12.1.2.172+
Fix from $2,300 2024-05-22
Veeam Backup \& Replication HIGH 8.8
CVE-2024-29850

Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

Fix: 12.1.2.172+
Fix from $1,950 2024-05-22
Veeam Service Provider Console CRITICAL 9.9
CVE-2024-29212

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and i…

Fix: 7.0.0.19551 / 8.0.0.19552+
Fix from $2,300 2024-05-14
Recovery Orchestrator HIGH 8.8
CVE-2024-22022

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the se…

Fix: 7.0+
Fix from $1,950 2024-02-07
One MEDIUM 5.4
CVE-2023-38549EPSS 19%

A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the accou…

Patch available
Fix from $1,600 2023-11-07
One CRITICAL 9.8
CVE-2023-38547EPSS 19%

A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur…

Patch available
Fix from $2,300 2023-11-07
Veeam Backup \& Replication HIGH 7.5
CVE-2023-27532 KEVEPSS 78%

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead…

Fix: 11.0.1.1261+
Fix from $1,950 2023-03-10
Veeam Backup For Google Cloud CRITICAL 9.8
CVE-2022-43549

Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

Mitigation only
Fix from $2,300 2022-12-05
Management Pack MEDIUM 6.1
CVE-2022-32225

A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vuln…

Patch available
Fix from $1,600 2022-07-14
Veeam Backup \& Replication CRITICAL 9.8
CVE-2022-26501 KEV

Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $2,300 2022-03-17
Veeam Backup \& Replication HIGH 8.8
CVE-2022-26500 KEVEPSS 6%

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API …

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $1,950 2022-03-17
Veeam Backup \& Replication HIGH 8.8
CVE-2022-26504

Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (…

Fix: 10.0.1.4854 / 11.0.1.1261+
Fix from $1,950 2022-03-17
Veeam HIGH 7.8
CVE-2022-26503

Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local s…

Fix: 4.0.2.2208 / 5.0.3.4708+
Fix from $1,950 2022-03-17
Veeam Backup \& Replication CRITICAL 9.8
CVE-2021-35971

Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserialization during Microsoft .NET remo…

Fix: 10.0.1.4854 / 11.0.0.837+
Fix from $2,300 2021-06-30
One Firmware HIGH 7.5
CVE-2020-15419EPSS 60%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…

Fix: 9.5.4.4587 / 10.0.0.750+
Fix from $1,950 2020-07-28
One Firmware HIGH 7.5
CVE-2020-15418EPSS 9%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…

Fix: 9.5.4.4587 / 10.0.0.750+
Fix from $1,950 2020-07-28
Veeam Availability Suite HIGH 8.8
CVE-2020-15518

VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged user…

Fix: 10.0+
Fix from $1,950 2020-07-03
One CRITICAL 9.8
CVE-2020-10915EPSS 87%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not r…

No fix yet
Fix from $2,300 2020-04-22