logo

Veeam warns of critical Backup Enterprise Manager auth bypass bug

ID: 1691aff9-e1af-5017-83ea-e5fdedc86992

STIX ID: report--1691aff9-e1af-5017-83ea-e5fdedc86992

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-21

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Veeam released patches for a critical Veeam Backup Enterprise Manager authentication bypass (CVE-2024-29849, CVSS 9.8) that permits unauthenticated account login, plus two other high-severity VBEM vulnerabilities (CVE-2024-29850 and CVE-2024-29851). The vendor advises upgrading to VBEM 12.1.2.172 or mitigating by stopping/disabling VeeamEnterpriseManagerSvc and VeeamRESTSvc or uninstalling VBEM; the report also highlights that previous Veeam vulnerabilities have been abused in ransomware campaigns affecting many organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.