Veeam
Veeam Recovery Orchestrator: vulnerabilidades y CVE
Veeam Recovery Orchestrator tiene 3 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-29855 | Crítica (9) | 22% | — | 11 jun 2024 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator |
| CVE-2024-22022 | Alta (8.8) | 0.70% | — | 7 feb 2024 | Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service. |
| CVE-2024-22021 | Media (4.3) | 0.40% | — | 7 feb 2024 | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to. |
Otros productos de Veeam
Veeam Backup & Replication · 42ONE · 12Veeam Service Provider Console · 8Veeam Agent FOR Windows · 3ONE Reporter · 3ONE Firmware · 2Backup AND Replication · 2Veeam Availability Suite · 1Veeam Backup FOR Google Cloud · 1Agent FOR Microsoft Windows · 1Veeam Software Appliance · 1Availability Orchestrator · 1