Access Control: Veeam Backup & Replication - Unauthenticated¶
Identifier:
cve_2024_40711
Scanner(s) Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner |
|---|---|---|
Description¶
A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).
Reference:
- https://x.com/codewhitesec/status/1831720125747069389?s=46
- https://www.veeam.com/kb4649
- https://nvd.nist.gov/vuln/detail/CVE-2024-40711
Configuration¶
Example¶
Example configuration:
Reference¶
assets_allowed¶
Type : List[AssetType]*
List of assets that this check will cover.
skip¶
Type : boolean
Skip the test if true.