CVE CVE

CVE-2024-40711

CISA Known Exploited Vulnerability (KEV)

Veeam Backup and Replication Deserialization Vulnerability

October 17, 2024

November 7, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Weakness Enumeration

CWE-ID CWE Name

CWE-502
Deserialization of Untrusted Data

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
9.8
Severity:

CRITICAL

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined