Description
Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19628 | Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service. |
References
| Link | Providers |
|---|---|
| https://veeam.com/kb4541 |
|
History
Tue, 03 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-06-03T18:40:07.375Z
Reserved: 2024-01-04T01:04:06.574Z
Link: CVE-2024-22022
Updated: 2024-08-01T22:35:34.824Z
Status : Modified
Published: 2024-02-07T01:15:08.487
Modified: 2025-06-03T19:15:37.243
Link: CVE-2024-22022
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD