logo

Critical Veeam Backup Enterprise Manager Flaw Allows Authentication Bypass

ID: 768f5a7d-f547-5fec-aa97-9a19a705501f

STIX ID: report--768f5a7d-f547-5fec-aa97-9a19a705501f

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-05-22

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Users of Veeam Backup Enterprise Manager are urged to update to version 12.1.2.172 to remediate multiple high- and critical-severity vulnerabilities — including an unauthenticated login bypass (CVE-2024-29849, CVSS 9.8) and a critical RCE in Veeam Service Provider Console (CVE-2024-29212, CVSS 9.9). The report highlights related NTLM relay/hash-theft issues and reminds readers that prior Veeam flaws have been exploited by groups such as FIN7 and Cuba to deploy malware and ransomware, increasing the urgency to patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.