PT-2024-9564 · Veeam · Veeam Backup & Replication

Published

2024-09-04

·

Updated

2024-10-19

·

CVE-2024-40714

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veeam Backup & Replication (affected versions not specified)
Description An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations. This issue can be exploited by a remote attacker to perform a man-in-the-middle (MITM) attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2024-11271
CVE-2024-40714

Affected Products

Veeam Backup & Replication