Database/Control plane, storage & DevOps
Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interface
CVSS 9.8CVE-2024-29849Control plane, storage & DevOpscurated
Impact
Unauthenticated users can log in as any user to the Enterprise Manager web interface
Who can reach it
Network (remote)
What to do
Control-plane: patch or decommission Enterprise Manager
References
Related entries
- CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCVE-2024-32053 · CyberPower PowerPanel platform - hardcoded database, service and cloud credentialsCritical
- CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authenticationCVE-2024-32735 · CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIsCritical
- CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, soCVE-2024-33625 · CyberPower PowerPanel business application - JWT signing keyCritical
- CyberPower PowerPanel business application - hardcoded authentication credentials: A hardcoded credential set compiledCVE-2024-34025 · CyberPower PowerPanel business application - hardcoded authentication credentialsCritical
- Volcano (v1.8.2 and earlier, service account token permissions): Volcano 1.8.2 ships over-permissive settings that letCVE-2024-36533 · Volcano (v1.8.2 and earlier, service account token permissions)Critical
- VMware vCenter Server (DCERPC heap overflow): A heap overflow in the DCERPC implementation lets an unauthenticatedCVE-2024-37080 · VMware vCenter Server (DCERPC heap overflow)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.