← back
CVE-2024-29855criticalCWE-798

CVE-2024-29855

55Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9epss 22%
from disclosure to weapon2 days
Published on NVDJun 11
1st PoC+2d
exploitation probability
22%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
In short

Veeam Recovery Orchestrator contains a hard-coded JWT secret that attackers can use to forge authentication tokens and bypass login requirements, allowing unauthorized access to the system.

Technical detail

The application uses a hard-coded JWT secret (CWE-798) for token generation, enabling attackers to craft valid authentication tokens without credentials. This allows direct authentication bypass and full system compromise without requiring valid user credentials or interaction.

Summary generated and translated by AI from the official description.
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.