Critical
CVSS: 9.1
A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
High
CVSS: 7.7
A vulnerability allowing a low-privileged user to extract saved SSH credentials.
Critical
CVSS: 9.9
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
High
CVSS: 8.8
A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.
Critical
CVSS: 9.9
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Critical
CVSS: 9.9
A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.
Critical
CVSS: 9.0
This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
Critical
CVSS: 9.0
This vulnerability allows a Backup or Tape Operator to write files as root.
Critical
CVSS: 9.0
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a
malicious password parameter.
High
CVSS: 7.8
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file.
High
CVSS: 8.8
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
Critical
CVSS: 9.9
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
High
CVSS: 7.8
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.
High
CVSS: 7.2
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.
High
CVSS: 8.8
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
High
CVSS: 8.8
A vulnerability allowing remote code execution (RCE) for domain users.
High
CVSS: 7.2
Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other…