Low-Privileged User Can Perform Local Privilege Escalation Through SSRF Vulnerability
CVE-2024-40718
8.8HIGH
What is CVE-2024-40718?
A vulnerability in Veeam's software allows low-privileged users to exploit server-side request forgery (SSRF) mechanisms. Through this vulnerability, attackers can potentially escalate their privileges locally, gaining unauthorized access to sensitive resources and compromising the security of the affected environment. This issue highlights the importance of safeguarding applications against SSRF attacks and emphasizes the necessity for rigorous security assessments of Veeam products.
Affected Version(s)
Nutanix AHV 12.6.0
Nutanix KVM 12.5.0