Veeam Security Update – 11 June 2024

Veeam has released a security update to fix a critical vulnerability across Veeam Recovery Orchestrator.

The addressed vulnerability could allow the remote attacker to gain access to the VRO web UI with administrative privileges in the affected system.

Veeam Recovery Orchestrator Gain Access Vulnerability (CVE-2024-29855):

  • CVSS: 9
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-29855

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Veeam Security Update

References