#VU101174 Permissions, Privileges, and Access Controls in Backup & Replication - CVE-2024-42453

 

#VU101174 Permissions, Privileges, and Access Controls in Backup & Replication - CVE-2024-42453

Published: December 3, 2024


Vulnerability identifier: #VU101174
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:U/U:Green
CVE-ID: CVE-2024-42453
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Backup & Replication
Software vendor:
Veeam

Description

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to application does not properly impose security restrictions. A remote user with a role assigned in the Users and Roles settings on the backup server can control and modify the configuration of connected virtual infrastructure hosts.


Remediation

Install updates from vendor's website.

External links