{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-40711/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-40711/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-40711/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-40711/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-40711/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-40711"},"sightings":{"href":"/api/v1/sightings/cve-2024-40711"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-40711.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-40711\n\ninfo:\n  name: Veeam Backup & Replication - Unauthenticated\n  author: rootxharsh,iamnoooob,DhiyaneshDK\n  severity: critical\n  description: |\n    A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).\n  impact: |\n    Unauthenticated attackers can exploit deserialization vulnerabilities to achieve remote code execution on Veeam Backup & Replication servers.\n  remediation: |\n    Update Veeam Backup & Replication to a patched version addressing CVE-2024-40711.\n  reference:\n    - https://x.com/codewhitesec/status/1831720125747069389?s=46\n    - https://www.veeam.com/kb4649\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-40711\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2024-40711\n    cwe-id: CWE-502\n    epss-score: 0.90369\n    epss-percentile: 0.99794\n  metadata:\n    verified: true\n    max-request: 1\n    shodan-query: html:\"Veeam Backup\"\n  tags: cve,cve2024,veeam,backup,unauth,passive,kev,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/api/v1/serverinfo\"\n    headers:\n      X-Api-Version: 1.1-rev1\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - '\"databaseVendor\":'\n          - '\"databaseContentVersion\":'\n        condition: and\n\n      - type: word\n        part: content_type\n        words:\n          - \"application/json\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022045f26f2af4c1091545f2488e5a1ae4eb4fbd23321f8704cfbcef81e788f02512022100f4ed29ca8d79ce066ab6171acfa53f061172d6125f7bdbd318dae46946b1b402:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-40711"}