Veeam Security Update – 10 November 2024

Veeam has released a security update to fix a vulnerability affecting Veeam Backup Enterprise Manager (VBEM).

The addressed vulnerability could allow the remote attacker to bypass the authentication while performing a Man-in-the-Middle (MITM) attack.

Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715):

  • CVSS: 7.7
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities

CVE-2024-40715

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Veeam Security Updates

References