Veeam Releases Security Advisory
The security advisory addresses one critical and three other vulnerabilities affecting Veeam Backup Enterprise Manager
Summary
The security advisory addresses one critical and three other vulnerabilities affecting Veeam Backup Enterprise Manager
Affected platforms
The following platforms are known to be affected:
Threat details
Unsupported versions of Veeam Backup & Replication
Vulnerability testing was only performed against actively supported versions of Veeam Backup & Replication.
Introduction
Veeam has released a security advisory addressing four vulnerabilities affecting Veeam Backup Enterprise Manager. The critical vulnerability CVE-2024-29849 has a CVSSv3.1 score of 9.8 and could allow an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user.
Three further vulnerabilities, two high and one low, were also addressed.
Proof-of-concept released for CVE-2024-29849
A proof-of-concept for the exploitation of CVE-2024-29849 has been publicly released. Exploitation is considered more likely.
Threat updates
| Date | Update |
|---|---|
| 11 Jun 2024 |
CVE information was added
The cyber alert has been updated to reflect this change |
| 11 Jun 2024 |
Proof-of-concept exploit code released for CVE-2024-29849
The cyber alert has been updated to reflect this change |
Remediation advice
Affected organisations are encouraged to review the Veeam Advisory kb4581 and apply the relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 11 June 2024 9:35 am