Loading...
Loading...
CVE-2024-29849 This vulnerability in Veeam Backup Enterprise Manager allows an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user. Severity: CriticalCVSS v3.1 Score: 9.8AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H This vulnerability was reported by Yashar Shahinzadeh (Voorivex Team). CVE-2024-29850 This Vulnerability in Veeam Backup Enterprise Manager allows account takeover via NTLM relay. Severity: HighCVSS v3.1 Score: 8.8AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H This vulnerability was reported by Yashar Shahinzadeh (Voorivex Team). CVE-2024-29851 This vulnerability in Veeam Backup Enterprise Manager allows a high-privileged user to steal the NTLM hash of the Veeam Backup Enterprise Manager service account if that service account is anything other than the default Local System account. Severity: HighCVSS v3.1 Score: 7.2AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2024-29852 This vulnerability in Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs. Severity: LowCVSS v3.1 Score: 2.7AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N This vulnerability was reported by Yashar Shahinzadeh (Voorivex Team).
All vulnerabilities documented in this article were fixed in Veeam Backup Enterprise Manager 12.1.2.172, which is packaged with: Veeam Backup & Replication 12.1.2 (build 12.1.2.172)
Vulnerability Mitigation For customers who are unable to upgrade Veeam Backup Enterprise Manager to 12.1.2.172 immediately, consider the following: This vulnerability can be mitigated by halting the Veeam Backup Enterprise Manager software. To do this, stop and disable the following services:Note: Disabling the services will not prevent installation of the 12.1.2 update. However, after updating, you'll need to reset the services back to Automatic startup. VeeamEnterpriseManagerSvc (Veeam Backup Enterprise Manager) VeeamRESTSvc (Veeam RESTful API Service)Note: On servers where both VBEM and VBR are installed, there will be two services with similar names. The service named 'Veeam Backup Server RESTful API Service' belongs to the Veeam Backup & Replication software and does not need to be stopped as part of this mitigation. This can be achieved using the following PowerShell commands:
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.