Network Alerts

Veeam Vulnerabilities

Posted by Matt Weber - September 18, 2024 - Vulnerability, Veeam

About the Alert

Veeam has announced several vulnerabilities within multiple products with critical and high severities. The disclosed vulnerabilities could allow a malicious, unauthenticated threat actor with network access to perform remote code execution, bypass authentication mechanisms, or obtain credentials, Specifics of the vulnerabilities can be found here.

Products Affected (12.1.2.172 and all earlier version 12 builds): 

Veeam Backup & Replication
Veeam ONE
Veeam Service Provider Console
Veeam Agent for Linux
Veeam Backup for Nutanix AHV
Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization

Key Takeaways:

  • Critical and high severity
  • Malicious actor(s) could perform remote code execution, bypass authentication mechanisms, or obtain credentials
  • Requires software update to address the vulnerabilities

Mitigating the Vulnerabilities

It is recommended to update affected Veeam instances. For those with a SafetyNet contract who utilize Veeam and impacted by this vulnerability, your SymQuest Account Executive will reach out to discuss a best go forward plan for remediation.

Never miss a critical vulnerability alert

Stay in the know and receive a notification right to your inbox when a security message is posted.

Subscribe

Subscribe to receive Network Alerts

×