CVE-2024-39718
HIGHDescription
An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service account.
Is your site exposed to CVE-2024-39718?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| veeam | veeam_backup_\&_replication |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-39718? +
How severe is CVE-2024-39718? +
What products are affected by CVE-2024-39718? +
How do I check if I'm vulnerable to CVE-2024-39718? +
Related Vulnerabilities
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the …
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent …
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user