Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-38581 | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations. |
| Link | Providers |
|---|---|
| https://www.veeam.com/kb4649 |
|
Thu, 01 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veeam veeam Backup \& Replication
|
|
| CPEs | cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Veeam veeam Backup \& Replication
|
|
| Metrics |
cvssV3_1
|
Mon, 09 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Veeam
Veeam backup \& Replication |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:veeam:backup_\&_replication:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Veeam
Veeam backup \& Replication |
|
| Metrics |
ssvc
|
Sat, 07 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations. | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-09T14:03:17.836Z
Reserved: 2024-07-09T01:04:07.426Z
Link: CVE-2024-40714
Updated: 2024-09-09T14:01:05.612Z
Status : Analyzed
Published: 2024-09-07T17:15:13.690
Modified: 2025-05-01T18:17:19.890
Link: CVE-2024-40714
No data.
OpenCVE Enrichment
No data.
EUVD