CVE-2024-42451

MEDIUM

Veeam Backup & Replication - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side. This exposes sensitive data, which could be used for further attacks, including unauthorized access to systems managed by the platform.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312 CWE-863
Status published
Products (1)
veeam/veeam_backup_\&_replication 12.0.0.1402 - 12.3.0.310
Published Dec 04, 2024
Tracked Since Feb 18, 2026