Skip to main content

Veeam Backup Enterprise Manager Vulnerability CVE-2024-40715


MarcoLuvisi
Forum|alt.badge.img+5

Release hotfix for:

Veeam Backup Enterprise Manager Vulnerability
(CVE-2024-40715)

This vulnerability in Veeam Backup Enterprise Manager allows attackers to bypass the authentication while performing a Man-in-the-Middle (MITM) attack.

Link to hotfix: https://www.veeam.com/kb4682

10 comments

waqasali
Forum|alt.badge.img+3
  • Influencer
  • 198 comments
  • November 6, 2024

Thank you for sharing this information. My question here did you face vulnerability in Veeam Backup Enterprise Manager.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8485 comments
  • November 6, 2024

Thanks for posting this one Marco.  I am going to investigate it and see what is required for patching it.


waqasali
Forum|alt.badge.img+3
  • Influencer
  • 198 comments
  • November 6, 2024

@Chris.Childerhose once complete pease share with us your investigation. 

 

I hope so your investigation will helpful for us.


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • November 10, 2024

Looks like just a .dll file is being patched:

  • Veeam.Backup.Enterprise.Core.dll

So pretty straight forward. 

To verify patch, run the following as per the KB 

Get-FileHash -Path 'C:\Program Files\Veeam\Backup and Replication\Enterprise Manager\Veeam.Backup.Enterprise.Core.dll' -Algorithm SHA1

The hash should be: FDC176FCE4825023F14462A51541C1DF591B28AC

If not, you are vulnerable.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8485 comments
  • November 10, 2024

The patch is very fast at install.  Only affects two services for VEM.


leduardoserrano
Forum|alt.badge.img+6
  • On the path to Greatness
  • 353 comments
  • November 11, 2024

Tks @MarcoLuvisi and @dips for the information!


  • New Here
  • 1 comment
  • November 12, 2024

That webpage has disappeared.


Dynamic
Forum|alt.badge.img+9
  • Veeam Vanguard
  • 380 comments
  • November 12, 2024
CBCCICTJL wrote:

That webpage has disappeared.

 

can confirm this. Yesterday it was available, i did a download on a customer installation. Has anyone more information why the KB is not online anymore, or is it a temporary problem?
Thanks Markus

 
 

 

 


Same here tired to get to the download page and its not working, any updates?


Dynamic
Forum|alt.badge.img+9
  • Veeam Vanguard
  • 380 comments
  • November 12, 2024

It’s available again πŸ™‚


Comment