Vulnerabilidades en Veeam

89 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Veeam apresenta uma taxa de exploração ativa 3,1 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado mesmo com volume total moderado de 72 CVEs. A CVE-2024-40711, atualmente a falha mais perigosa em exploração ativa, registra EPSS de 0,8819 — valor que aponta alta probabilidade de exploração em ambiente real e deve ser tratado com prioridade máxima de remediação. O tipo de falha mais recorrente é CWE-94 (injeção de código), padrão que tende a viabilizar execução remota e comprometimento profundo de sistemas de backup, categoria de ativo historicamente visada por agentes de ransomware. Com 25 CVEs críticas, 6 com PoC pública disponível e 5 surgidas nos últimos 90 dias, o cenário exige monitoramento contínuo e aplicação rigorosa de patches.

CVE-2026-58071HIGHA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal AdministEPSS 0.4%CVE-2024-45204HIGHA vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved EPSS 0.4%CVE-2024-40714HIGHAn improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitiveEPSS 0.4%CVE-2026-58074HIGHA vulnerability allowing a high-privileged user to execute arbitrary code on the server.EPSS 0.4%CVE-2025-23082HIGHVeeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unaEPSS 0.3%CVE-2024-42453HIGHA vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructEPSS 0.3%CVE-2026-58073CRITICALA vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent'sEPSS 0.3%CVE-2024-40713HIGHA vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor AutheEPSS 0.3%CVE-2024-42021HIGHAn improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.EPSS 0.3%CVE-2024-40712HIGHA path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege esEPSS 0.3%CVE-2024-42022HIGHAn incorrect permission assignment vulnerability allows an attacker to modify product configuration files.EPSS 0.3%CVE-2026-58075HIGHA vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privilEPSS 0.3%CVE-2024-42451HIGHA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by caEPSS 0.3%CVE-2026-64631HIGHA vulnerability allowing a low-privileged user to inject SQL and extract database contents.EPSS 0.3%CVE-2024-45206MEDIUMA vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts ofEPSS 0.2%CVE-2025-24287MEDIUMA vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with eleEPSS 0.2%CVE-2026-64630MEDIUMA vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.EPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2024-29853HIGHAn authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.EPSS 0.2%CVE-2026-64632HIGHA vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.EPSS 0.2%