Veeam Software, a leading backup, recovery, and data management solutions provider, has announced the discovery and remedy of several critical and high-severity vulnerabilities across multiple products.
These vulnerabilities were identified during internal testing and through external reports, highlighting potential risks for users of Veeam Backup & Replication, Veeam ONE, Veeam Agent for Linux, Veeam Service Provider Console, and other Veeam products.
CVE-2024-40711 is a critical vulnerability that allows unauthenticated remote code execution (RCE) and was reported by Florian Hauser of CODE WHITE GmbH, with a CVSS score of 9.8.
CVE-2024-40713 and CVE-2024-40710 are high-severity vulnerabilities, enabling low-privileged users to alter Multi-Factor Authentication (MFA) settings and execute remote code, respectively.
Additionally, CVE-2024-39718 allows low-privileged users to remove files remotely, carrying a CVSS score of 8.1. Other vulnerabilities include issues with TLS certificate validation and local privilege escalation.
Veeam has addressed these vulnerabilities in the latest software updates, urging all users to upgrade to the following versions:
Users are strongly advised to update to the latest versions to mitigate potential security risks. Veeam continues to prioritize security and encourages customers to remain vigilant and proactive in applying updates.
Download Free Incident Response Plan Template for Your Security Team – Free Download
APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…
The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…
Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…
A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…