Skip to main content

Veeam Releases Security Advisory

The security advisory addresses one critical and three other vulnerabilities affecting Veeam Backup Enterprise Manager

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

The security advisory addresses one critical and three other vulnerabilities affecting Veeam Backup Enterprise Manager


Threat details

Unsupported versions of Veeam Backup & Replication

Vulnerability testing was only performed against actively supported versions of Veeam Backup & Replication.


Introduction

Veeam has released a security advisory addressing four vulnerabilities affecting Veeam Backup Enterprise Manager. The critical vulnerability CVE-2024-29849 has a CVSSv3.1 score of 9.8 and could allow an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user. 

Three further vulnerabilities, two high and one low, were also addressed.

Proof-of-concept released for CVE-2024-29849

A proof-of-concept for the exploitation of CVE-2024-29849 has been publicly released. Exploitation is considered more likely.


Threat updates

Date Update
11 Jun 2024 CVE information was added

The cyber alert has been updated to reflect this change

11 Jun 2024 Proof-of-concept exploit code released for CVE-2024-29849

The cyber alert has been updated to reflect this change


Remediation advice

Affected organisations are encouraged to review the Veeam Advisory kb4581 and apply the relevant updates.


Definitive source of threat updates


Last edited: 11 June 2024 9:35 am