First published: Sat Sep 07 2024(Updated: )
A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-40713 is classified as medium due to its potential to allow low-privileged users to bypass Multi-Factor Authentication.
To fix CVE-2024-40713, ensure that only high-privileged users have access to modify Multi-Factor Authentication settings.
CVE-2024-40713 affects multiple versions of Veeam Backup & Replication prior to the security updates addressing this vulnerability.
CVE-2024-40713 can impact user security by allowing unauthorized modifications to MFA settings, potentially leading to account takeovers.
Mitigation for CVE-2024-40713 includes implementing strict role-based access controls and regularly auditing user permissions.