Critical Veeam Backup Enterprise Manager Flaw Allows Authentication Bypass
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-27532 | Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile). Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials. | 7.5 | 78% | KEV ransomware |
| largetens of thousands of deployments, of which thousands are internet-exposed (estimate) | |
| CVE-2024-29212 | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its component Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine. NVD description · AI analysis pending | 9.9 | 2% |
| — | ||
| CVE-2024-29849 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. NVD description · AI analysis pending | 9.8 group max | 38% |
| — | ||
| CVE-2024-29853 | An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. NVD description · AI analysis pending | 7.8 | <1% |
| — |
Full article326 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 22, 2024Enterprise Security / Vulnerability
Users of Veeam Backup Enterprise Manager are being urged to update to the latest version following the discovery of a critical security flaw that could permit an adversary to bypass authentication protections.
Tracked as CVE-2024-29849 (CVSS score: 9.8), the vulnerability could allow an unauthenticated attacker to log in to the Veeam Backup Enterprise Manager web interface as any user.
The company has also disclosed three other shortcomings impacting the same product -
- CVE-2024-29850 (CVSS score: 8.8), which allows account takeover via NTLM relay
- CVE-2024-29851 (CVSS score: 7.2), which allows a privileged user to steal NTLM hashes of a Veeam Backup Enterprise Manager service account if it's not configured to run as the default Local System account
- CVE-2024-29852 (CVSS score: 2.7), which allows a privileged user to read backup session logs
All the flaws have been addressed in version 12.1.2.172. However, Veeam noted that deploying Veeam Backup Enterprise Manager is optional and that environments that do not have it installed are not impacted by the flaws.
In recent weeks, the company has also resolved a local privilege escalation flaw affecting the Veeam Agent for Windows (CVE-2024-29853, CVSS score: 7.2) and a critical remote code execution bug impacting Veeam Service Provider Console (CVE-2024-29212, CVSS score: 9.9).
"Due to an unsafe deserialization method used by the Veeam Service Provider Console (VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine," Veeam said of CVE-2024-29212.
Security flaws in Veeam Backup & Replication software (CVE-2023-27532, CVSS score: 7.5) have been exploited by threat actors like FIN7 and Cuba for deploying malicious payloads, including ransomware, making it imperative that users move quickly to patch the aforementioned vulnerabilities.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/critical-veeam-backup-enterprise.html