S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 15, 2024

CVE-2024-40711 Scanner

CVE-2024-40711 scanner - Remote Code Execution (RCE) vulnerability in Veeam Backup & Replication

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-40711
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Backup and Recoveryby Veeam
12.1.2
backup_\&_replicationby veeam
0
Updated Aug 22, 2026View on NVD →
Detail

Veeam Backup & Replication is widely used by enterprises for data protection and disaster recovery across various platforms, including virtual, physical, and cloud-based environments. This software assists in ensuring business continuity by backing up critical infrastructure, applications, and data. System administrators and IT professionals utilize it for centralized management and control of backup processes. Additionally, the software is commonly implemented in data centers where security and data protection are paramount. Its extensive use across industries highlights the importance of securing it against vulnerabilities like Remote Code Execution.

The Remote Code Execution vulnerability within Veeam Backup & Replication allows attackers to execute arbitrary code on a target server. This vulnerability stems from deserialization of untrusted data, potentially permitting unauthorized code injection. Exploiting this flaw may lead to compromise of sensitive data or system instability. Given its critical nature, this vulnerability poses a high risk to organizations using this software.

The vulnerability affects the Veeam Backup & Replication API, particularly through the /api/v1/serverinfo endpoint, which may allow unauthenticated access to backend services. The vulnerability exploits deserialization of untrusted data, making it possible for an attacker to submit malicious payloads to gain execution control. By crafting specific requests that bypass normal authorization, the attacker can manipulate the system to run code at their discretion. The issue primarily involves the X-Api-Version header, which when set to a certain value, triggers the vulnerability. This flaw highlights the need for enhanced input validation to mitigate exploitation risks.

Possible Effects:

  • Unauthorized system access leading to potential theft of sensitive data.
  • Remote execution of arbitrary code, compromising the integrity and availability of the system.
  • Service disruption due to unauthorized modifications and command execution.
  • Escalation of access privileges, allowing attackers to expand their reach across connected systems and databases.

S4E provides proactive exposure management tools to help organizations detect and mitigate vulnerabilities like the RCE in Veeam Backup & Replication before they can be exploited. By using S4E, organizations can automate their vulnerability management and ensure continuous monitoring of their digital assets. Members benefit from tailored security scans, actionable reports, and an easy-to-use dashboard, allowing them to stay ahead of potential cyber threats. Sign up today to keep your systems secure and compliant.

References:

Solution Advice
  • Update to the latest version of Veeam Backup & Replication to apply security patches.
  • Implement input validation to prevent untrusted data from being deserialized.
  • Restrict access to the /api/v1/serverinfo endpoint to trusted IP addresses.
  • Monitor system logs for unusual API activity or access attempts.
  • Consider enabling two-factor authentication (2FA) to reduce unauthorized access risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.