← back
CVE-2024-29849criticalCWE-287

CVE-2024-29849

55Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 17%
from disclosure to weapon19 days
Published on NVDMay 22
1st PoC+19d
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

An attacker can log into Veeam Backup Enterprise Manager as any user without needing a password or credentials. This is critical because it gives unauthorized access to backup systems that protect important company data.

Technical detail

An unauthenticated attacker can bypass authentication mechanisms (CWE-287) in the Enterprise Manager web interface to assume the identity of any legitimate user. This requires network access to the web interface and allows complete compromise of backup management functionality, including data access and system configuration.

Summary generated and translated by AI from the official description.
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.