Uncredentialed attackers could gain administrative control of backup infrastructure
π’ Advisory Summary
Vendor: Veeam
Affected Product: Backup Enterprise Manager (All versions β€ 12.1.2.172)
Vulnerability Type: Authentication Bypass (CWE-287)
CVSSv3 Score: 9.8 (Critical)
Attack Vector: Network-accessible HTTP interface
π Technical Impact
Successful exploitation allows:
β Full administrative access to backup management console
β Unauthorized data restoration/deletion
β Potential credential harvesting from backup jobs
β Chain attacks with other vulnerabilities
π‘οΈ Mitigation Steps
Immediate Action: Upgrade to Veeam Backup Enterprise Manager 12.1.3 or later
Interim Measures:
Restrict network access to TCP ports 9392/tcp (web UI)
Enable MFA for all backup administrator accounts
Audit logs for [Unauthorized] AdminLogin events
Detection: Monitor for anomalous login patterns from unexpected IPs
π Vendor Response
Veeam has released patches and published KB article [KB4567]. No workarounds exist for unpatched systems.
π Additional Resources
Veeam Security Advisory VSA-2024-0123
#Cybersecurity #Veeam #PatchNow #CVE202429849 #InfoSec
Similar
-
CVE-2024-7954: Critical RCE in SPIP's Porte Plume Plugin CVE-2024-7954: Critical RCE in SPIP's Porte Plume Plugin 2024-7954 (Cross-platform)
-
CVE-2024-22567: Security Advisory for MCMS 5.3.5 CVE-2024-22567: Security Advisory for MCMS 5.3.5 2024-22567 (Cross-platform)
-
CVE-2024-11616: Buffer Overflow in Netskope Endpoint DLP CVE-2024-11616: Buffer Overflow in Netskope Endpoint DLP 2024-11616 (Cross-platform)
-
CVE-2024-21182: Broken Access Control in Oracle WebLogic Server CVE-2024-21182: Broken Access Control in Oracle WebLogic Server 2024-21182: (Cross-platform)
Top Softwares
-
CVE-2021-24508: WordPress Smash Balloon Plugin XSS Vulnerability CVE-2021-24508: WordPress Smash Balloon Plugin XSS Vulnerability 2021-24508 (Cross-platform)
-
App Builder (x64) β Complete Application Development Suite App Builder (x64) β Complete Application Development Suite 2025.7 (64-bit)
-
EE - Videohive - Text Number MOGRT EE - Videohive - Text Number MOGRT 58123788 (Cross-platform)
-
Opera Opera 32.1 (64-bit)
-
WinRAR for Windows WinRAR for Windows 1.9 (64-bit)
Featured
-
π‘οΈ Visual Protector 0.5 β Advanced File Binder & Process Protection Tool π‘οΈ Visual Protector 0.5 β Advanced File Binder & Process Protection Tool Latest (64-bit)
-
π Shell FINDER V-7 β Fast & Efficient Website Shell Detection Tool π Shell FINDER V-7 β Fast & Efficient Website Shell Detection Tool Latest (64-bit)
-
π·οΈ Zeus RAT 2025 β Legacy of the Infamous Banking Trojan & Modern Threats π·οΈ Zeus RAT 2025 β Legacy of the Infamous Banking Trojan & Modern Threats Latest (64-bit)
-
π οΈ sqlMapGUI 2.0 β User-Friendly SQL Injection & Database Vulnerability Tool π π οΈ sqlMapGUI 2.0 β User-Friendly SQL Injection & Database Vulnerability Tool π Latest (64-bit)
-
π» SSH RAT Keylogger Crypter 2025 β Ultimate Remote Access & Stealth Tool π‘οΈ π» SSH RAT Keylogger Crypter 2025 β Ultimate Remote Access & Stealth Tool π‘οΈ Latest (64-bit)