Vulnerabilities
Vulnerable Software
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVSS Score
9.9
EPSS Score
0.003
Published
2026-03-12
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
CVSS Score
9.9
EPSS Score
0.003
Published
2026-03-12
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-03-12
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
CVSS Score
9.9
EPSS Score
0.002
Published
2025-10-31
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVSS Score
8.8
EPSS Score
0.003
Published
2025-10-31
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
CVSS Score
7.2
EPSS Score
0.001
Published
2025-06-19
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
CVSS Score
9.9
EPSS Score
0.006
Published
2025-06-19
A vulnerability allowing remote code execution (RCE) for domain users.
CVSS Score
9.9
EPSS Score
0.258
Published
2025-03-20
A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, such as modifying the trusted client certificate used for authentication on a specific port. This can result in unauthorized access, enabling the user to call privileged methods and initiate critical services. The issue arises due to insufficient permission requirements on the method, allowing users with low privileges to perform actions that should require higher-level permissions.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-12-04
A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a remote management interface. This can be achieved using a session object that allows for credential enumeration and exploitation, leading to the leak of plaintext credentials to a malicious host. The attack is facilitated by improper usage of a method that allows operators to add a new host with an attacker-controlled IP, enabling them to retrieve sensitive credentials in plaintext.
CVSS Score
7.7
EPSS Score
0.002
Published
2024-12-04


Contact Us

Shodan ® - All rights reserved