Loading...
Loading...
CVE-2024-29855 A vulnerability (CVE-2024-29855) in Veeam Recovery Orchestrator (VRO) version 7.0.0.337 allows an attacker to access the VRO web UI with administrative privileges. Note: The attacker must know the exact username and role of an account that has an active VRO UI access token to accomplish the hijack. Severity: CriticalCVSS 3.1 Score: 9.0CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The vulnerability discussed in this article was resolved starting in: Veeam Recovery Orchestrator 7.1.0.230 Veeam Recovery Orchestrator 7.0.0.379
New Veeam Recovery Orchestrator Release All customers are advised to upgrade their Veeam Recovery Orchestrator deployment to version 7.1.0.278 or higher. Note: Veeam Recovery Orchestrator 7.1.0.278 is included within VeeamDataPlatform_23H2_20240825.iso.
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.