First published: Sat Sep 07 2024(Updated: )
A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a low-privileged role within Veeam Backup & Replication.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40710 is classified as a high-severity vulnerability due to its potential for remote code execution.
To fix CVE-2024-40710, you should apply the latest security patches provided by Veeam for Backup & Replication.
CVE-2024-40710 enables exploitation that can lead to remote code execution and extraction of sensitive credentials.
CVE-2024-40710 affects users with low-privileged roles within Veeam Backup & Replication.
The potential consequences of CVE-2024-40710 include unauthorized remote access and the compromise of sensitive data.