Database/Control plane, storage & DevOps
Veeam Backup & Replication: Deserialization of untrusted data
CVSS 9.8CVE-2024-40711Control plane, storage & DevOpsKnown exploitedcurated
Impact
Deserialization of untrusted data -> unauthenticated remote code execution
Who can reach it
Network (remote)
What to do
Control-plane: URGENT - the backup server owns the restore path; patch, isolate, rotate
References
Related entries
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverCVE-2025-23120 · Veeam Backup & ReplicationHigh
- Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup ServerCVE-2025-23121 · Veeam Backup & ReplicationHigh
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedCVE-2023-27532 · Veeam Backup & ReplicationHigh
- Fluent Bit: "Linguistic Lumberjack" - memory corruption parsing trace requests in the embedded HTTP serverCVE-2024-4323 · Fluent BitCritical
- Fortinet FortiManager: "FortiJump" - missing authentication in fgfmdCVE-2024-47575 · Fortinet FortiManagerCritical
- GitHub Enterprise Server: Forged SAML response with encrypted assertions enabledCVE-2024-4985 · GitHub Enterprise ServerCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.