https://login.veeam.com/en/oauth?client_id=nXojRrypJ8&redirect_uri=https%3A%2F%2Fwww.veeam.com%2Fservices%2Fauthentication%2Fredirect_url&response_type=code&scope=profile&state=eyJmaW5hbFJlZGlyZWN0TG9jYXRpb24iOiJodHRwczovL3d3dy52ZWVhbS5jb20va2IzMTQ0IiwiaGFzaCI6ImRjNWQxYWExLTQ4M2MtNDYyNC1iMGJlLTU1NzZlNzQ1OWI3ZiJ9
1-800-691-1991 | 9am - 8pm ET
EN

Veeam ONE Remote Code Execution Vulnerabilities

Challenge

Vulnerabilities in Veeam ONE Agent components residing on Veeam ONE and Veeam Backup & Replication servers allow executing malicious code remotely without authentication. This may lead to gaining control over the target system.
Severity: critical
CVSS v3 score: 9.8

Cause

Veeam ONE Agent uses .NET data serialization mechanisms. The remote attacker may send malicious code to the TCP port opened by Veeam ONE Agent (TCP 2805 by default) which will not be deserialized properly. The deserialization of untrusted data is performed during TLS Handshake (vulnerability tracked as ZDI-CAN-10400 and CVE-2020-10914) and during logging of error messages (vulnerability tracked as ZDI-CAN-10401 and CVE-2020-10915).

Solution

Hotfixes are available for the following Veeam ONE versions:
  • 10 (build 10.0.0.750)
  • 9.5 Update 4a (build 9.5.4.4587) 
NOTE: These hotfixes are not compatible with version 9.5 Update 4 (build 9.5.4.4566). Customers running this version are advised to upgrade to version 10 or 9.5 Update 4a using updated ISO images.

The hotfix must be installed on the Veeam ONE server. Veeam ONE Agents on the Veeam Backup & Replication servers will be updated automatically after installing the hotfix. After applying the updates your Veeam ONE Agent version will be 10.0.1.750 on Veeam ONE version 10 servers and 9.5.5.4587 on Veeam ONE 9.5 Update 4a servers.

User-added image

Please note, that all new deployments of Veeam ONE version 10 and version 9.5 Update 4a installed using the ISO images downloaded after 04/15/2020 are not vulnerable.

More information

These vulnerabilities were discovered by:
Michael Zanetta & Edgar Boda-Majer from Bugscale working with Trend Micro Zero Day Initiative.

DOWNLOAD HOTFIX FOR Veeam ONE 10


MD5: 39ca33e5c9c0fec534ad5d2e87987985
SHA1: f42676d7997d57504944f02116e842b7ce4f3358

DOWNLOAD HOTFIX FOR Veeam ONE 9.5 U4a


MD5: 89817e0eeac0d0434218b928a1d0e918
SHA1: a78af22d463be8c0d2255cfdf732f210298a251d

 
KB ID:
3144
Product:
Veeam ONE
Version:
9.5 U4, 9.5 U4a, 10
Published:
2020-04-15
Last Modified:
2020-08-13
Please rate how helpful this article was to you:
5 out of 5 based on 1 ratings
Thank you for helping us improve!
An error occurred during voting. Please try again later.

Couldn't find what you were looking for?

Below you can submit an idea for a new knowledge base article.
Report a typo on this page:

Please select a spelling error or a typo on this page with your mouse and press CTRL + Enter to report this mistake to us. Thank you!

Spelling error in text

Knowledge base content request
By submitting, you agree that your personal data will be managed by Veeam in accordance with the Privacy Policy.
Your report was sent to the responsible team. Our representative will contact you by email you provided.
We're working on it please try again later