Researcher warns of a PoC exploit released for a critical vulnerability in Veeam Recovery Orchestrator.

The vulnerability is tracked as CVE-2024-29855 and allows for bypass authentication. Thanks to the PoC exploit developed by security researcher Sina Kheirkhah, the chances of exploitation increase. In fact, a detailed post about the vulnerability and its exploitation has been published.
Veeam Recovery Orchestrator: Authentication bypass
CVE-2024-29855 is rated critical with a rating of 9/10. It allows authentication bypass and affects Veeam Recovery Orchestrator (VRO) versions 7.0.0.337 and 7.1.0.205 and earlier.
See also: Veeam: PoC exploit released for critical vulnerability in VBEM
The flaw allows unauthenticated attackers to log in to the Veeam Recovery Orchestrator web UI with administrator privileges.
The issue arises from the use of a hardcoded JSON Web Token (JWT) secret, which allows attackers to generate valid JWT tokens for any user, including administrators.
The Veeam bulletin recommends upgrading to patched versions 7.1.0.230 and 7.0.0.379 to protect against the vulnerability. It also lists the prerequisites required to exploit the flaw, which include knowing a valid username and role and targeting a user with an active session.
"The attacker must know the exact username and role of an account that has a VRO UI access token to perform the breach," Veeam says.
However, in the PoC exploit for the vulnerability in Veeam Recovery Orchestrator, researcher Kheirkha says that some of these prerequisites can be bypassed, making exploitation easier.
Role
Kheirkhah found that role definition can be easily bypassed, as there are only a few roles (DRSiteAdmin, DRPlanAuthor, DRplanOperator, and SiteSetupOperator).
See also: Kyndryl and Veeam partner on cybersecurity services
The exploit script was designed to iterate between these roles when generating JWT tokens, until a match is made.

User name
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
To find a username for the attack, the researcher notes that the SSL certificate, obtained simply by connecting to the target endpoint, usually contains enough clues to extract the domain and possible usernames ( for a token spraying attack).
Active session
Finally, regarding the “active session” requirement, Kheirkhah's PoC script creates and tests JWT tokens at a range of timestamps to increase the chances of achieving an active session.
With the Veeam Recovery Orchestrator vulnerability exploit now publicly available, attackers will begin attacks very soon, so it is crucial to apply available security updates immediately
Organizations should take this exploit as a wake-up call to always prioritize the immediate implementation of security. Waiting to address vulnerabilities can leave systems and sensitive data at risk.
See also: Black Basta ransomware exploited Windows zero-day vulnerability
Additionally, organizations should regularly conduct security audits and penetration tests to uncover potential vulnerabilities before attackers can exploit them. This proactive approach can help prevent such attacks in the first place.
Finally, it is important for organizations to adopt a strong security culture and encourage employees to report any suspicious activity or vulnerability they may encounter. With the ever-evolving cyber threat landscape ,it is essential for organizations to remain vigilant and protect their systems and data.
Source: www.bleepingcomputer.com
