First published: Wed May 22 2024(Updated: )
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam Backup Enterprise Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29849 is a critical severity vulnerability affecting Veeam Backup Enterprise Manager.
To fix CVE-2024-29849, update Veeam Backup Enterprise Manager to the latest patched version released by Veeam.
Any user of Veeam Backup Enterprise Manager is potentially affected due to the authentication bypass issue.
CVE-2024-29849 can be exploited by unauthenticated users who gain unauthorized access to the Enterprise Manager web interface.
CVE-2024-29849 was disclosed publicly in May 2024.