Exploit for critical Veeam auth bypass available, patch now
ID: f72cc17b-6f6d-5f9a-a1fa-e4e4f51ac552
STIX ID: report--f72cc17b-6f6d-5f9a-a1fa-e4e4f51ac552
Feed Name: Bleeping Computer
Veeam Backup Enterprise Manager (VBEM) has a critical authentication bypass (CVE-2024-29849) in its REST API service (Veeam.Backup.Enterprise.RestAPIService.exe) listening on TCP port 9398; a public proof-of-concept demonstrates how an attacker can send a crafted VMware SSO token that causes VBEM to validate against an attacker-controlled URL and gain administrator access. Veeam published a security bulletin and urges immediate upgrade to VBEM version 12.1.2.172, while the report also lists mitigations (restrict access, firewall rules, MFA, WAF, log monitoring, and isolation) for those unable to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
