CVE-2024-29855: Critical severity veeam recovery orchestrator vulnerability
Published Jun 11, 2024
·Updated
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Affected Software
3 affected components
Veeam Recovery Orchestrator
Veeam Recovery Orchestrator<7.0.0.379
Veeam Recovery Orchestrator>=7.1<7.1.0.230
Event History
Jun 11, 2024
CVE Published
via MITRE·03:55 AM
Data Sourced
via MITRE·03:55 AM
DescriptionSeverity
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 13, 2024
News Published
via BleepingComputer·05:21 PM
News Published
via BleepingComputer·05:21 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-29855?
CVE-2024-29855 is considered critical due to its potential for authentication bypass.
2
How do I fix CVE-2024-29855?
To fix CVE-2024-29855, update Veeam Recovery Orchestrator to the latest patched version provided by Veeam.
3
What type of vulnerability is CVE-2024-29855?
CVE-2024-29855 is a hard-coded secret vulnerability that allows an attacker to bypass authentication.
4
Which software is affected by CVE-2024-29855?
CVE-2024-29855 affects Veeam Recovery Orchestrator.
5
What can happen if CVE-2024-29855 is exploited?
Exploiting CVE-2024-29855 can lead to unauthorized access to Veeam Recovery Orchestrator functionalities.