PT-2024-9558 · Veeam · Veeam Backup & Replication

Published

2024-09-04

·

Updated

2024-10-19

·

CVE-2024-40713

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veeam Backup & Replication (affected versions not specified)
Description A vulnerability exists that allows a user with a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and bypass MFA. This issue is related to weaknesses in the authentication procedure, which can be exploited by an attacker to change MFA settings and circumvent existing security restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-11265
CVE-2024-40713

Affected Products

Veeam Backup & Replication