← Vulnerability feed

Vulnerability record · CVE-2020-10914 · published 22 April 2020

CVE-2020-10914: Veeam ONE Agent unauthenticated .NET deserialization RCE

Veeam · One

Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the PerformHandshake method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service to remote code execution.

9.8 CVSS 3.1 Critical EPSS 48% · top 1.2% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the PerformHandshake method. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-10400.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable deserialization leading to code execution as a service account, with a CVSS of 9.8 and very high EPSS.

What it is

Veeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the PerformHandshake method, allowing deserialization of untrusted data. Because the flaw is reachable without authentication over the network, it exposes the service to remote code execution.

Impact

An attacker can execute arbitrary code in the context of the Veeam ONE Agent service account, which typically carries broad privileges over the monitored environment.

Attack surface

Reached over the network via the agent's handshake interface; the CVSS vector (AV:N/PR:N/UI:N) and description confirm no authentication or user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.479 (98.8th percentile), and public technical write-ups exist via Packet Storm and ZDI.

What to do

  • Apply the vendor fix referenced in Veeam KB3144 for Veeam ONE Agent 9.5.4.4587.
  • Restrict network access to the Veeam ONE Agent handshake port to trusted management hosts only.
  • Run the agent service under a least-privilege account rather than a highly privileged service account.
  • Monitor for and block unexpected inbound connections to agent endpoints from untrusted segments.

Detection

  • Alert on Veeam ONE Agent service crashes or restarts that may indicate malformed deserialization payloads.
  • Monitor for child processes spawned by the Veeam ONE Agent service, especially shells or scripting hosts.
  • Inspect network traffic to agent handshake ports for anomalous or oversized serialized payloads.
  • Review agent service account activity for unexpected command execution or lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10914 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38547Veeam one information exposure vulnerabilityA vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configur…EPSS 19%9.8CVE-2020-10915Veeam ONE Agent unauthenticated .NET deserialization RCEVeeam ONE Agent 9.5.4.4587 fails to validate user-supplied data in the HandshakeResult method, allowing deserialization of untrusted data. Because th…EPSS 87%analysed8.8CVE-2024-42023Veeam one improper access control vulnerabilityAn improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.EPSS 0.47%8.8CVE-2024-42024Veeam one execution with unnecessary privileges vulnerabilityA vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the mach…EPSS 1.3%8.0CVE-2024-42019Veeam one information exposure vulnerabilityA vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction …EPSS 0.54%6.5CVE-2024-42021Veeam one improper access control vulnerabilityAn improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.EPSS 0.30%5.4CVE-2024-42020Veeam one cross-site scripting vulnerabilityA Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection.EPSS 0.41%5.4CVE-2023-38549Veeam one cross-site scripting vulnerabilityA vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the accou…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2020-10914), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.