Uncredentialed attackers could gain administrative control of backup infrastructure
π’ Advisory Summary
Vendor: Veeam
Affected Product: Backup Enterprise Manager (All versions β€ 12.1.2.172)
Vulnerability Type: Authentication Bypass (CWE-287)
CVSSv3 Score: 9.8 (Critical)
Attack Vector: Network-accessible HTTP interface
π Technical Impact
Successful exploitation allows:
β Full administrative access to backup management console
β Unauthorized data restoration/deletion
β Potential credential harvesting from backup jobs
β Chain attacks with other vulnerabilities
π‘οΈ Mitigation Steps
Immediate Action: Upgrade to Veeam Backup Enterprise Manager 12.1.3 or later
Interim Measures:
Restrict network access to TCP ports 9392/tcp (web UI)
Enable MFA for all backup administrator accounts
Audit logs for [Unauthorized] AdminLogin events
Detection: Monitor for anomalous login patterns from unexpected IPs
π Vendor Response
Veeam has released patches and published KB article [KB4567]. No workarounds exist for unpatched systems.
π Additional Resources
Veeam Security Advisory VSA-2024-0123
#Cybersecurity #Veeam #PatchNow #CVE202429849 #InfoSec
Top Softwares
-
Opera Opera 32.1 (64-bit)
-
WinRAR for Windows WinRAR for Windows 1.9 (64-bit)
-
microG Services (Signed APK) microG Services (Signed APK) v0.3.1.4.240913 (Android)
-
Face Swap β AI Photo Editor (Pro Mod APK) Face Swap β AI Photo Editor (Pro Mod APK) v1.1.5 (Android)
-
Tele Latino Premium TV (Mod APK) Tele Latino Premium TV (Mod APK) NA (Android)
Featured
-
Dell EMC Certification Prep Guide to Core Technologies Course Dell EMC Certification Prep Guide to Core Technologies Course Level: Beginner (Cross platform)
-
CVE-2024-29849 Critical Authentication Bypass in Veeam Backup Enterprise Manager CVE-2024-29849 Critical Authentication Bypass in Veeam Backup Enterprise Manager 2024-29849 (Linux)
-
π¬ Deadpool 2 β Watch Online Free in HD! π¬ Deadpool 2 β Watch Online Free in HD! 2018 (Cross platform)
-
Internet Download Manager (IDM) β Official Download Accelerator Internet Download Manager (IDM) β Official Download Accelerator Latest (64-bit)
-
IntraWEB Ultimate - Professional Web Application Framework IntraWEB Ultimate - Professional Web Application Framework 16.0.11 (64-bit)