Exploit for Veeam Recovery Orchestrator auth bypass available, patch now
ID: 8577c3c7-eddb-5adc-b237-62e64fcefdfd
STIX ID: report--8577c3c7-eddb-5adc-b237-62e64fcefdfd
Feed Name: Bleeping Computer
Threat Score
A critical authentication bypass (CVE-2024-29855, CVSS 9.0) affects Veeam Recovery Orchestrator versions 7.0.0.337 and 7.1.0.205 and earlier due to a hardcoded JWT secret, allowing unauthenticated administrative access; a public PoC exploit demonstrating username/role enumeration and token-timestamp techniques has been published and vendors have released patched versions (7.1.0.230 and 7.0.0.379) that should be applied promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
