🔐 CVE Alert

CVE-2024-22021

MEDIUM 6.5
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retrieve plans from a Scope other than the one they are assigned to.

Vendor veeam
Product recovery orchestrator
Published Feb 7, 2024
Last Updated Mar 2, 2026
Stay Ahead of the Next One

Get instant alerts for veeam recovery orchestrator

Be the first to know when new medium vulnerabilities affecting veeam recovery orchestrator are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected Versions

Veeam / Recovery Orchestrator
6 < 6
Veeam / Disaster Recovery Orchestrator
5 < 5
Veeam / Availability Orchestrator
4 < 4
Veeam / Recovery Orchestrator
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
veeam.com: https://veeam.com/kb4541