← Back to browse · API

CVE-2024-40711

Severity
CRITICAL
CVSS
9.8
EPSS
0.90369
Risk score
56.63
CISA KEV
Yes
PoC
No
Published
2024-09-07
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-38578, GHSA-C76V-GJQC-J462
Products
Veeam:Backup & Replication, Veeam:Backup and Recovery 12.1.2 ≤12.1.2
Sources
cisa.gov CVE-2024-40711
euvd EUVD-2024-38578

Description

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

References