{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aveeamveeam_backup_%5C_replication/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:veeam:veeam_backup_\\\u0026_replication:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-29849"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Veeam ONE"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-access","monitoring"],"_cs_type":"advisory","_cs_vendors":["Veeam"],"content_html":"\u003cp\u003eVeeam has disclosed a security vulnerability affecting Veeam ONE that permits a remote, unauthenticated attacker to bypass existing security controls. The flaw primarily impacts the monitoring and reporting capabilities of the application. By exploiting this weakness, an attacker could potentially gain unauthorized access to the Veeam ONE interface or manipulate its monitoring functions without needing legitimate credentials. This vulnerability poses a significant risk to organizations relying on Veeam ONE for infrastructure visibility and backup oversight. Defenders should prioritize patching, as this vulnerability represents an initial access vector into a sensitive management component of the IT environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables remote, unauthenticated attackers to circumvent security safeguards within Veeam ONE. This can lead to unauthorized access to backup monitoring data, potentially exposing infrastructure configurations or enabling further exploitation of the backup environment. The number of affected instances is potentially high given the widespread deployment of Veeam solutions in enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the deployment of the vendor-supplied security patch for Veeam ONE to address CVE-2024-29849. Ensure that the Veeam ONE dashboard and management interfaces are not directly exposed to the internet. Review access logs for any suspicious unauthenticated connection attempts originating from untrusted network segments.\u003c/p\u003e\n","date_modified":"2026-08-26T14:05:37Z","date_published":"2026-08-26T14:05:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-veeam-one-bypass/","summary":"A vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.","title":"Veeam ONE Security Bypass Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-veeam-one-bypass/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:veeam:veeam_backup_\\\u0026_replication:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2024-40713"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Backup \u0026 Replication"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["Veeam"],"content_html":"\u003cp\u003eThe German Federal Office for Information Security (BSI) has released a security advisory regarding a local information disclosure vulnerability within Veeam Backup \u0026amp; Replication. This flaw enables an authenticated local attacker to bypass existing security controls and access sensitive information stored or processed by the application. Because the vulnerability requires local access, the scope is primarily limited to environments where an attacker has already established a foothold on the underlying host operating system. The vulnerability is tracked as CVE-2024-40713. Defenders should prioritize auditing access controls on systems hosting Veeam Backup \u0026amp; Replication services and ensure that local user privileges are strictly enforced to minimize the risk of lateral movement or privilege escalation resulting from this disclosure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the integrity and confidentiality of backup environments. If successfully exploited, an attacker could extract sensitive data such as backup metadata, configurations, or credentials, which could facilitate further unauthorized access across the enterprise network. This impact is particularly severe in backup systems, which often hold centralized keys or administrative access to the entire infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the application of vendor-provided security patches that address CVE-2024-40713 on all affected Veeam Backup \u0026amp; Replication server instances. Audit local user accounts and groups on Windows hosts running Veeam services to ensure the principle of least privilege is applied, particularly restricting access for non-administrative accounts that might interact with Veeam directories or local API endpoints. Review service account permissions to ensure they are not over-privileged, limiting the potential information an attacker could harvest if the service context is compromised.\u003c/p\u003e\n","date_modified":"2026-08-26T14:04:57Z","date_published":"2026-08-26T14:04:57Z","id":"https://feed.craftedsignal.io/briefs/2026-08-veeam-info-disclosure/","summary":"A local information disclosure vulnerability in Veeam Backup \u0026 Replication, identified as CVE-2024-40713, allows authenticated local attackers to gain unauthorized access to sensitive data.","title":"Information Disclosure Vulnerability in Veeam Backup \u0026 Replication","url":"https://feed.craftedsignal.io/briefs/2026-08-veeam-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:veeam:veeam_backup_\\\u0026_replication:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}