CVE-2024-42024
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
All CVEs associated with "Veeam ONE". Page 1/1 • 12 CVEs.
A curated feed of “Veeam ONE”-related CVEs appears below. We currently track 12 CVEs for this tag (all time). In the last 365 days, 0 were published. Average CVSS is 7.2 (all time), and 58% are rated High/Critical (all time). Top CWEs (all time): CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-611 - Improper Restriction of XML External Entity Reference, CWE-502 - Deserialization of Untrusted Data.
In our taxonomy this topic maps to a LOW impact class. Backup and DR systems hold credentials and full data copies. Patch promptly, validate backup and restore paths, restrict admin access, and encrypt repositories. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | Premier Support | EOL | LTS |
|---|---|---|---|---|---|
| 13 | 13.0.2.6723 | Unavailable | - | ||
| 12 | 12.3.0.4670 | ||||
| 11 | 11.0.1.1880 | Expired | |||
| 10 | 10.0.2.1094 | Expired | |||
| 9.5 | 9.5.4.4587 | Expired | |||
| 9.0 | 9.0.0.2088 | Unavailable | - Expired | ||
| 8.0 | 8.0.0.1669 | Unavailable | - Expired | ||
| 7.0 | 7.0.0.949 | Unavailable | - Expired | ||
| 6.5 | 6.5.0.686 | Unavailable | - Expired | ||
| 6.0 | 6.0.0.520 | Unavailable | - Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Veeam ONE” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where the Veeam ONE Agent is installed.
A vulnerability in Veeam ONE allows a user with the Veeam ONE Read-Only User role to view the Dashboard Schedule. Note: The criticality of this vulnerability is reduced because the user with the Read…
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note:…
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execu…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability.…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability.…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specifi…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specifi…
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
Veeam ONE Reporter 9.5.0.3201 allows CSRF.