Vulnerabilidades en VEEAM

86 resultados
Análisis Vexday

A Veeam apresenta um perfil de risco contido com apenas 2 vulnerabilidades registradas, ambas críticas, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-502 - desserialização insegura) é típica de plataformas de backup complexas, porém sem incidentes de ataque documentados até o momento. O risco é historicamente estável, sem descobertas recentes nos últimos 90 dias.

CVE-2026-64633CRITICALA vulnerability allowing remote unauthenticated code execution on the agent host.EPSS 0.3%CVE-2024-40714HIGHAn improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitiveEPSS 0.3%CVE-2024-42453HIGHA vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructEPSS 0.3%CVE-2024-40713HIGHA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor AutheEPSS 0.3%CVE-2026-58067HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.EPSS 0.3%CVE-2024-42021HIGHAn improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.EPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2024-42022HIGHAn incorrect permission assignment vulnerability allows an attacker to modify product configuration files.EPSS 0.3%CVE-2026-58071HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal AdministEPSS 0.3%CVE-2026-58075HIGHA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privilEPSS 0.3%CVE-2024-42451HIGHA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by caEPSS 0.3%CVE-2026-64631HIGHA vulnerability allowing a low-privileged user to inject SQL and extract database contents.EPSS 0.3%CVE-2024-45206MEDIUMA vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts ofEPSS 0.2%CVE-2026-64630MEDIUMA vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.EPSS 0.2%CVE-2025-24287MEDIUMA vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with eleEPSS 0.2%CVE-2026-58073CRITICALA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent'sEPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2024-29853HIGHAn authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.EPSS 0.2%CVE-2026-64635MEDIUMImproper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attEPSS 0.2%CVE-2024-40709HIGHA missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.EPSS 0.2%