VYPR

Veeam Backup \& Replication

by Veeam

CVEs (46)

  • CVE-2024-42456HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result…

  • CVE-2024-42452HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges to system-level access. This allows the attacker to upload files to the server with elevated privileges.…

  • CVE-2024-40717HigDec 4, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These jobs can be configured to run pre- and post-scripts, which can be located on a network share and are executed…

  • CVE-2024-40710HigSep 7, 2024
    risk 0.57cvss 8.8epss 0.01

    A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and passwords). Exploiting these vulnerabilities requires a user who has been assigned a…

  • CVE-2024-29850HigMay 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

  • CVE-2022-26504HigMar 17, 2022
    risk 0.57cvss 8.8epss 0.02

    Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe

  • CVE-2020-15518HigJul 3, 2020
    risk 0.57cvss 8.8epss 0.01

    VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.

  • CVE-2026-32997HigMay 28, 2026
    risk 0.56cvss —epss 0.01

    A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

  • CVE-2024-42455HigDec 4, 2024
    risk 0.54cvss 8.1epss 0.15

    A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary file collection. This exploit allows the attacker to delete any file on the system with service…

  • CVE-2024-40714HigSep 7, 2024
    risk 0.54cvss 8.3epss 0.00

    An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

  • CVE-2024-42453HigDec 4, 2024
    risk 0.53cvss 8.1epss 0.00

    A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power off virtual machines, delete files in storage, and make configuration changes, potentially…

  • CVE-2024-39718HigSep 7, 2024
    risk 0.53cvss 8.1epss 0.01

    An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.

  • CVE-2024-42019HigSep 7, 2024
    risk 0.52cvss 8.0epss 0.01

    A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data collected from Veeam Backup & Replication.

  • CVE-2025-55125HigJan 8, 2026
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

  • CVE-2024-40713HigSep 7, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA.

  • CVE-2024-40712HigSep 7, 2024
    risk 0.51cvss 7.8epss 0.00

    A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

  • CVE-2026-21670HigMar 12, 2026
    risk 0.50cvss 7.7epss 0.00

    A vulnerability allowing a low-privileged user to extract saved SSH credentials.

  • CVE-2024-40715HigNov 7, 2024
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform Man-in-the-Middle (MITM) attack to exploit this vulnerability.

  • CVE-2025-24286HigJun 19, 2025
    risk 0.48cvss 7.2epss 0.19

    A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.

  • CVE-2024-29851HigMay 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.