CVE-2024-29852
CVE-2024-29852 allows privileged users within Veeam Backup Enterprise Manager to access and read backup session logs. This vulnerability exposes sensitive data contained within these logs. With an SVRS score of 30, while not critical, it indicates a potential risk that should be monitored. Although the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) suggests a degree of concern, especially given the "In The Wild" tag. The ability for high-privileged users to read backup logs can lead to information disclosure and potentially further compromise if the logs contain sensitive credentials or configuration details. While immediate action may not be required, a thorough review of access controls and monitoring of user activity is recommended to mitigate the risks associated with CVE-2024-29852. This emphasizes the importance of going beyond CVSS scores when assessing vulnerability risk. The vulnerability's presence "In The Wild" should not be taken lightly.
Description
CVE-2024-29852 is a vulnerability in Veeam Backup Enterprise Manager that allows high-privileged users to read backup session logs. This could allow an attacker to gain access to sensitive information, such as the contents of backups, the names of users who have accessed backups, and the dates and times of backups.
Key Insights
- The SVRS of 30 indicates that this vulnerability is of low severity and does not require immediate action.
- The vulnerability is actively exploited in the wild, meaning that attackers are actively using it to target systems.
- The Cybersecurity and Infrastructure Security Agency (CISA) has not issued a warning about this vulnerability.
Mitigation Strategies
- Update Veeam Backup Enterprise Manager to the latest version.
- Restrict access to backup session logs to only those users who need it.
- Monitor backup logs for any suspicious activity.
Additional Information
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.