Veeam
by Veeam
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-40718 | Hig | 0.57 | 8.8 | 0.00 | Sep 7, 2024 | A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability. | ||
| CVE-2024-39718 | Hig | 0.53 | 8.1 | 0.01 | Sep 7, 2024 | An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account. | ||
| CVE-2024-40712 | Hig | 0.51 | 7.8 | 0.00 | Sep 7, 2024 | A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE). | ||
| CVE-2024-42021 | Med | 0.42 | 6.5 | 0.00 | Sep 7, 2024 | An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials. | ||
| CVE-2025-24287 | Med | 0.40 | 6.1 | 0.00 | Jun 19, 2025 | A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions. | ||
| CVE-2024-42022 | Med | 0.34 | 5.3 | 0.00 | Sep 7, 2024 | An incorrect permission assignment vulnerability allows an attacker to modify product configuration files. | ||
| CVE-2024-45204 | Med | 0.28 | 4.3 | 0.00 | Dec 4, 2024 | A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial… |
- risk 0.57cvss 8.8epss 0.00
A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.
- risk 0.53cvss 8.1epss 0.01
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
- risk 0.51cvss 7.8epss 0.00
A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).
- risk 0.42cvss 6.5epss 0.00
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
- risk 0.40cvss 6.1epss 0.00
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
- risk 0.34cvss 5.3epss 0.00
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
- risk 0.28cvss 4.3epss 0.00
A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using retrieved credentials to expose sensitive NTLM hashes, impacting systems beyond the initial…