{"id":163534,"date":"2024-05-22T18:01:17","date_gmt":"2024-05-22T18:01:17","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=163534"},"modified":"2024-05-22T18:01:18","modified_gmt":"2024-05-22T18:01:18","slug":"veeam-backup-enterprise-manager-cve-2024-29849","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/163534\/security\/veeam-backup-enterprise-manager-cve-2024-29849.html","title":{"rendered":"Critical Veeam Backup Enterprise Manager authentication bypass bug"},"content":{"rendered":"
<\/div>\n

A critical security vulnerability in Veeam Backup Enterprise Manager could allow threat actors to bypass authentication.<\/h2>\n\n\n\n

A critical vulnerability, tracked as\u00a0CVE-2024-29849\u00a0(CVSS score: 9.8), in Veeam Backup Enterprise Manager could allow attackers to bypass authentication.<\/p>\n\n\n\n

Veeam Backup Enterprise Manager is a centralized management and reporting tool designed to simplify the administration of Veeam Backup & Replication environments. It offers a web-based interface that allows users to manage multiple Veeam Backup & Replication servers, monitor backup jobs, and generate reports.<\/gwmw><\/p>\n\n\n\n

<\/gwmw>This vulnerability in\u00a0Veeam Backup Enterprise Manager<\/strong>\u00a0allows an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user.” reads the advisory<\/a> published by the vendor.<\/p>\n\n\n\n

The company has addressed the following vulnerabilities in Veeam Backup Enterprise Manager:<\/p>\n\n\n\n