CERT-In Advisory
CIAD-2024-0049
Multiple Vulnerabilities in Veeam Products
Original Issue Date: October 15, 2024
Severity Rating: High
Software Affected
- Veeam Backup & Replication
- Veeam ONE
- Veeam Service Provider Console
- Veeam Agent for Linux
- Veeam Backup for Nutanix AHV
- Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization
Overview
Multiple vulnerabilities have been reported in Veeam Products which could allow an attacker to execute arbitrary code, escalate privileges, bypass security restrictions and disclose sensitive information on the targeted system.
Description
Multiple vulnerabilities have been reported in Veeam products; details of which are provided below:
Note: It is reported that threat actors are actively exploiting the vulnerability (CVE-2024-40711, affecting Veeam Backup & Replication product that allows for unauthenticated remote code execution) for deploying Ransomware. Users are advised to apply patches urgently.
Solution
Apply appropriate fixes as mentioned in Security Advisory:
https://www.veeam.com/kb4649
Vendor Information
Veeam
https://www.veeam.com/kb4649
References
Veeam
https://www.veeam.com/kb4649
CVE Name
CVE-2024-39715
CVE-2024-39714
CVE-2024-39718
CVE-2024-38650
CVE-2024-38651
CVE-2024-40709
CVE-2024-40710
CVE-2024-40711
CVE-2024-40712
CVE-2024-40713
CVE-2024-40714
CVE-2024-40718
CVE-2024-42019
CVE-2024-42020
CVE-2024-42021
CVE-2024-42022
CVE-2024-42023
CVE-2024-42024
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|