CISA Known Exploited Vulnerability (KEV)
Veeam Backup and Replication Deserialization Vulnerability
October 17, 2024
November 7, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-502 |
Deserialization of Untrusted Data |