Authentication Bypass by Capture-replay in Veeam Backup Enterprise Manager - CVE-2024-40715

 

Authentication Bypass by Capture-replay in Veeam Backup Enterprise Manager - CVE-2024-40715

Published: November 7, 2024 / Updated: November 18, 2024


Vulnerability identifier: #VU99997
CSH Severity: Medium
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40715
CWE-ID: CWE-294
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an unspecified error in the authentication process. A remote non-authenticated attacker can perform a man-in-the-middle (MitM) attack to capture traffic between the application and its users and use it to gain unauthorized access to the application.


Affected software

Veeam Backup Enterprise Manager

How to mitigate CVE-2024-40715

Install updates from vendor's website.

Veeam Backup Enterprise Manager - update to 12.2.0.334 TF812030

External References

Related Security Bulletins