Several vulnerabilities have been identified in Veeam products. The vulnerabilities could allow for Remote Code Execution (RCE), Privilege Escalation, Credential Exposure, and more. The vulnerabilities have High and Critical CVSS scores, the highest being 9.8 out of 10.
Veeam released security patches for several of its products, including Veeam Backup & Replication (VBR), Veeam ONE, Veeam Service Provider Console (VSPC), and more. The numerous vulnerabilities addressed range from credential interception over the network to MFA bypass and unauthenticated RCE on server components.
The most critical of the vulnerabilities is CVE-2024-40711 (CVSS 9.8) and resides on the Veeam Backup & Replication component, allowing for full RCE with no authentication. Other critical or high-risk vulnerabilities for the software include CVE-2024-40710, CVE-2024-42024, CVE-2024-42023, CVE-2024-39714, CVE-2024-39715, CVE-2024-38651.
Since the vulnerabilities were discovered through internal Veeam security audits, no public knowledge of the exploitation specifics or proof-of-concept exploits currently exist; however, it is safe to assume that threat actors are interested in producing working exploits to begin taking advantage of the weaknesses as fast as possible, so prompt patching is highly recommended.