CyberzSOC

Publication detail
← Back to advisories & guidance

2024-048: Critical Vulnerability in Veeam Backup Enterprise Manager ↗ source

May 22, 2024 CERT-EU Advisory

Summary

The vulnerability CVE-2024-29849 , with a CVSS score of 9.8, could allow an unauthenticated attacker to login into the Veeam Backup Enterprise Manager web interface as any user. The flaw lies in the authentication mechanism of the web interface. The vulnerability CVE-2024-29850 , with a CVSS score of 8.8, could allow account takeover via The vulnerability CVE-2024-29851 , with a CVSS score of 7.2, could allow a high-privileged user to steal the NTLM hash of the Veeam Backup Enterprise Manager service account if that service account is anything other than the default Local System account. Veeam Backup Enterprise Manager versions before prior to 12.1.2.172 are affected. It is strongly advised upgrading to the latest version as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-29849 9.8 Critical Veeam Backup & Replication Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
CVE-2024-29850 8.8 High Veeam Backup & Replication Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
CVE-2024-29851 7.2 High Veeam Backup & Replication Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.