📦 Recovery Orchestrator

by Veeam

🔍 What is Recovery Orchestrator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-29855

CRITICAL CVSS 9.0 Jun 11, 2024

CVE-2024-29855 is a critical authentication bypass vulnerability in Veeam Recovery Orchestrator caused by a hard-coded JWT secret. Attackers can forge valid authentication tokens to gain unauthorized ...

CVE-2024-22022

HIGH CVSS 8.8 Feb 7, 2024

CVE-2024-22022 allows low-privileged Veeam Recovery Orchestrator users to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service. This could enable attackers to perf...