CVE-2024-40714: high-severity vulnerability in Veeam Backup and Recovery
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.3epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
Veeam · Backup and RecoveryRelated CVEs — Veeam Backup and Recovery
In the same product, most dangerous first.
References
https://www.veeam.com/kb4649