<feed xmlns="http://www.w3.org/2005/Atom">
 <title type="text">Veeam Security Advisory</title>
 <id>https://www.veeam.com/services/open/kb/security-feed</id>
 <link rel="alternate" type="text/html" href="https://www.veeam.com/knowledge-base.html"/>
 <link rel="self" type="application/atom+xml" href="https://www.veeam.com/services/open/kb/security-feed"/>
 <updated>2026-04-16T19:35:57Z</updated>
 <author>
     <name>Veeam Software</name>
 </author>
<entry>
 <title><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 13.0.1.2067]]></title>
 <link href="https://www.veeam.com/kb4831"/> 
 <id>https://www.veeam.com/kb4831</id>
 <updated>2026-03-12T00:00:00Z</updated>
 <published>2026-03-12T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 13.0.1.2067]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Vulnerabilities Resolved in Veeam Backup &amp; Replication 13.0.1.2067</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4831</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 13</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2026-03-12</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2026-04-16</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__text veeam-text">
               All vulnerabilities documented in this article were resolved in <a href="https://www.veeam.com/kb4738" target="_blank" rel="noopener">Veeam Backup &amp; Replication 13.0.1.2067</a>.
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-b07ed759ab" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   All vulnerabilities disclosed in this article affect <b>Veeam Backup &amp; Replication&nbsp;13.0.1.1071</b>&nbsp;and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 13 builds</a>. 
                   <br>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21669</b></h4>
                   <p>A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9</span><br><b>Affected Deployment Type: </b>Windows-based Veeam Backup &amp; Replication<br><b>Source:</b> Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21670</b></h4>
                   <p>A vulnerability allowing a low-privileged user to extract saved SSH credentials.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.7<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</span></span><br><b>Affected Deployment Type: </b>Windows-based Veeam Backup &amp; Replication | Veeam Software Appliance<br><b>Source:</b> Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21671</b></h4>
                   <p>A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup &amp; Replication.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.1<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Affected Deployment Type: </b>Veeam Software Appliance<br><b>Source:</b> Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21672</b></h4>
                   <p>A vulnerability allowing local privilege escalation on Windows-based Veeam Backup &amp; Replication servers.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Affected Deployment Type:</b> Windows-based Veeam Backup &amp; Replication<br><b>Source:</b>&nbsp;Reported through HackerOne.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21708</b></h4>
                   <p>A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the <code>postgres</code> user.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L</span></span><br><b>Affected Deployment Type:</b> Windows-based Veeam Backup &amp; Replication | Veeam Software Appliance<br><b>Source:</b> Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21709</b></h4>
                   <p>A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.</p>
                   <p><b>Severity:</b>&nbsp;Medium<br><b>CVSS v3.1 Score:</b> <span class="veeam-tooltip">6.7<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L</span></span><br><b>Source: </b>Reported through HackerOne.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Other Resolved Security-related Issues</b></h4>
                   <ul>
                    <li>Veeam Agent <i>for Linux</i> —&nbsp;Updated the port range that the software will open in the machine's firewall to align with other Veeam products. Veeam Agent <i>for Linux</i> will now open ports 2500-3300.</li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <p>These vulnerabilities were fixed starting with the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4738" target="_blank" rel="noopener">Veeam Backup &amp; Replication 13.0.1.2067</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4465]]></title>
 <link href="https://www.veeam.com/kb4830"/> 
 <id>https://www.veeam.com/kb4830</id>
 <updated>2026-03-12T00:00:00Z</updated>
 <published>2026-03-12T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4465]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Vulnerabilities Resolved in Veeam Backup &amp; Replication 12.3.2.4465</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4830</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2026-03-12</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2026-04-16</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__text veeam-text">
               All vulnerabilities documented in this article were resolved in <a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2.4465</a>.
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-6a3971b31c" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   All vulnerabilities disclosed in this article affect <b>Veeam Backup &amp; Replication&nbsp;12.3.2.4165</b>&nbsp;and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>. 
                   <br>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21666</b></h4>
                   <p>A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Reported by&nbsp;HackerOne.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21667</b></h4>
                   <p>A vulnerability allowing&nbsp;an authenticated domain user to perform remote code execution (RCE) on the Backup Server.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Discovered during internal testing.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21668</b></h4>
                   <p>A vulnerability allowing&nbsp;an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source: </b>Discovered during internal testing.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21672</b></h4>
                   <p>A vulnerability allowing local privilege escalation on Windows-based Veeam Backup &amp; Replication servers.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source:</b> Reported through HackerOne.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21708</b></h4>
                   <p>A vulnerability allowing&nbsp;a Backup Viewer to perform remote code execution (RCE) as the <code>postgres</code> user.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L</span></span><br><b>Source: </b>Discovered during internal testing.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2026-21709</b></h4>
                   <p>A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.</p>
                   <p><b>Severity:</b>&nbsp;Medium<br><b>CVSS v3.1 Score:</b> <span class="veeam-tooltip">6.7<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L</span></span><br><b>Source: </b>Reported through HackerOne.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Other Resolved Security-related Issues</b></h4>
                   <ul>
                    <li>Veeam Agent <i>for Linux</i> — Updated the port range that the software will open in the machine's firewall to align with other Veeam products. Veeam Agent <i>for Linux</i> will now open ports 2500-3300.</li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <p>These vulnerabilities were fixed starting with the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2.4465</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[List of Security Fixes and Improvements in Veeam Agent for Linux]]></title>
 <link href="https://www.veeam.com/kb3109"/> 
 <id>https://www.veeam.com/kb3109</id>
 <updated>2026-03-12T00:00:00Z</updated>
 <published>2026-03-12T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Agent for Linux]]></name>
 </author>
 <summary><![CDATA[This article describes all security-related fixes and improvements introduced in each release or update of Veeam Agent for Linux.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
  <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">List of Security Fixes and Improvements in Veeam Agent <i>for Linux</i></h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
        <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">3109</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Agent <i>for Linux</i> | 4.0 | 5.0 | 6.0 | 6.1 | 6.2 | 6.3 | 6.3.1 | 6.3.2 | 13</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2020-03-02</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2026-03-12</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
       <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Purpose</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>This article describes all security-related fixes and improvements introduced in each release or update of Veeam Agent <i>for Linux</i>.</p>
                  <p>The goal of this article is to provide our customers' security and compliance teams with the detailed information on security improvements between releases, in order to help them make an informed decision on whether it is critical to upgrade from their current Veeam Agent <i>for Linux</i> version to a latter one.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Security Fixes and Improvements</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <h4><b>13.0.1.404</b></h4>
                  <ul>
                   <li>The port range opened on the host firewall was changed to 2500-3300.</li>
                  </ul>
                  <h4><b>13.0.1.94</b></h4>
                  <ul>
                   <li>OpenSSL upgraded to version 3.0.17<br><br></li>
                  </ul>
                  <h4><b>13.0.0.0.772</b></h4>
                  <ul>
                   <li>OpenSSL upgraded to version 3.0.8<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>6.3.2.1307</b></h4>
                  <ul>
                   <li>The port range opened on the host firewall was changed to 2500-3300.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>6.2.0.101</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4649#valissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-40709</a>&nbsp;vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>6.1.0.1498</b></h4>
                  <ul>
                   <li>OpenSSL library updated to 1.0.2zi.</li>
                   <li>LZ4 library updated to 1.9.4.</li>
                   <li>Updated zlib library to 1.2.13.</li>
                   <li>Stronger backup encryption. -&nbsp;<i>(See pg. 7 of&nbsp;<a href="https://www.veeam.com/veeam_backup_12_1_whats_new_wn.pdf" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.1 What's New PDF</a>)<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>6.0.2.1168</b></h4>
                  <ul>
                   <li>OpenSSL Library updated to the newest version (1.0.2zg).<br><br></li>
                  </ul>
                  <h4><b>5.0.2.4707</b></h4>
                  <ul>
                   <li>OpenSSL was updated to v1.0.2zi.</li>
                   <li>liblz4 was updated to v1.9.4.</li>
                   <li>zlib was updated to v1.2.13.</li>
                   <li>PuTTY was updated to 0.80.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>5.0.0.4318</b></h4>
                  <ul>
                   <li>Addressed an issue with insecure default permissions of files created in /tmp</li>
                   <li>LZ4 compression library version has been updated to version 1.9.2.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>4.0.1.2365</b></h4>
                  <ul>
                   <li>Sensitive information used by managed Linux agent may get logged in the Linux operating system logs.</li>
                   <li>Creating an SMB repository using CLI command causes plain text password to be logged in the Veeam debug log.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>4.0.0.1961</b></h4>
                  <ul>
                   <li>An issue of insecure file permissions was addressed (vulnerability reported by RACK911 Labs).</li>
                   <li>OpenSSL was updated to version 1.0.2t.</li>
                  </ul>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  As we're establishing this new process, we appreciate any feedback on the content or format of this KB article. Please let us know in the <a href="https://forums.veeam.com/vmware-vsphere-f24/include-security-fixes-in-release-notes-t56818.html" target="_blank" rel="noopener">corresponding topic</a> on the Veeam Community Forums. If your feedback is <a href="https://en.wikipedia.org/wiki/Responsible_disclosure" target="_blank" rel="noopener">too sensitive to be shared publicly</a>, please submit it by <a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">opening a support case</a>. We highly appreciate your collaboration!
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #ADACAF; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[List of Security Fixes and Improvements in Veeam Backup & Replication]]></title>
 <link href="https://www.veeam.com/kb3103"/> 
 <id>https://www.veeam.com/kb3103</id>
 <updated>2026-03-12T00:00:00Z</updated>
 <published>2026-03-12T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[This article describes all security-related fixes and improvements introduced in each release or update of Veeam Backup & Replication.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
  <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">List of Security Fixes and Improvements in&nbsp;Veeam Backup &amp; Replication</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
        <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">3103</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 10 | 11 | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 | 13<br>
                  Veeam Cloud Connect | 10 | 11 | 12 | 12.2 | 12.3 | 12.3.1 | 12.3.2 | 13</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2020-03-02</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2026-03-12</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
       <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Purpose</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>This article describes all security-related fixes and improvements introduced in each release or update of Veeam Backup &amp; Replication.</p>
                  <p>The goal of this article is to provide our customers' security and compliance teams with detailed information on security improvements between releases, in order to help them make an informed decision on whether it is critical to upgrade from their current Veeam Backup &amp; Replication version to a latter one.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Security Fixes and Improvements</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <h4><b>13.0.1.2067</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4831" target="_blank" rel="noopener">CVE-2026-21669</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4831" target="_blank" rel="noopener">CVE-2026-21670</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4831" target="_blank" rel="noopener">CVE-2026-21671</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4831" target="_blank" rel="noopener">CVE-2026-21672</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4831" target="_blank" rel="noopener">CVE-2026-21708</a>&nbsp;vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>13.0.1.1071</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4792" target="_blank" rel="noopener">CVE-2025-55125</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4792" target="_blank" rel="noopener">CVE-2025-59468</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4792" target="_blank" rel="noopener">CVE-2025-59469</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4792" target="_blank" rel="noopener">CVE-2025-59470</a>&nbsp;vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>13.0.1.180</b></h4>
                  <ul>
                   <li>OpenSSL upgraded to version 3.0.17</li>
                   <li>Microsoft.IdentityModel.JsonWebTokens upgraded to version 8.12.0</li>
                   <li>System.Security.Cryptography.Xml upgraded to version 8.0.2</li>
                   <li>Microsoft.AspNetCore.Server.Kestrel.Core upgraded to version 2.3.6</li>
                   <li>Microsoft.AspNetCore.Server.Kestrel.Transport.Sockets upgraded to version 2.3.0<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>13.0.0.4967</b></h4>
                  <ul>
                   <li>Communication protocol was switched to gRPC</li>
                   <li>OpenSSL upgraded to version 3.0.8</li>
                   <li>Libxml2 upgraded to version 2.13.8</li>
                   <li>Microsoft.AspNetCore.Server.Kestrel.Core upgraded to version 2.3.0</li>
                   <li>Newtonsoft.Json upgraded to version 13.0.1</li>
                   <li>RestSharp upgraded to version 112.1.0</li>
                   <li>Microsoft.Extensions.Caching.Memory upgraded to version 8.0.1</li>
                   <li>System.Text.Json upgraded to version 8.0.5</li>
                   <li>Microsoft.AspNetCore.Identity upgraded to version 2.3.1<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.3.2.4465</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4830" target="_blank" rel="noopener">CVE-2026-21666</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4830" target="_blank" rel="noopener">CVE-2026-21667</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4830" target="_blank" rel="noopener">CVE-2026-21668</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4830" target="_blank" rel="noopener">CVE-2026-21672</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4830" target="_blank" rel="noopener">CVE-2026-21708</a>&nbsp;vulnerability was fixed.</li>
                   <li>Decode-uri-component upgraded to version 0.2.2</li>
                   <li>Newtonsoft.Json upgraded to version 13.0.3</li>
                   <li>Path-to-RegExp upgraded to version 1.9.0<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.3.2.4165</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4771" target="_blank" rel="noopener">CVE-2025-48983</a> vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4771" target="_blank" rel="noopener">CVE-2025-48984</a> vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.3.2.3617</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4743" target="_blank" rel="noopener">CVE-2025-23121</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4724" target="_blank" rel="noopener">CVE-2025-24286</a>&nbsp;vulnerability was fixed.</li>
                   <li>Azure.Identity upgraded to version 1.11.4</li>
                   <li>Microsoft.Identity.Client upgraded to version 4.61.3</li>
                   <li>Sustainsys.Saml2 upgraded to version 2.11.0<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.3.1.1139</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4724" target="_blank" rel="noopener">CVE-2025-23120</a>&nbsp;vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.3.0.310</b></h4>
                  <ul>
                   <li>curl upgraded to version 8.10.1</li>
                   <li>Fixed a security flaw that allowed an attacker to intercept credentials during the initial connection to a Proxmox server.<br><i>Reported by Peter Panholzer.</i></li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-40717</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-42451</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-42452</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-42453</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-42455</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-42456</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-42457</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4693" title="Follow link" target="_blank" rel="noopener">CVE-2024-45204</a>&nbsp;vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.2.0.334</b></h4>
                  <ul>
                   <li>npgsql upgraded to 6.0.11</li>
                   <li>libxml upgraded to version 2.13.3</li>
                   <li>curl upgraded to version 8.8.0</li>
                   <li><a href="https://www.veeam.com/kb4649#vbrissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-39718</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4649#vbrissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-40710</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4649#vbrissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-40711</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4649#vbrissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-40712</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4649#vbrissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-40713</a>&nbsp;vulnerability was fixed.</li>
                   <li><a href="https://www.veeam.com/kb4649#vbrissue" title="Follow link" target="_blank" rel="noopener">CVE-2024-40714</a>&nbsp;vulnerability was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.1.2.172</b></h4>
                  <ul>
                   <li>PuTTY updated to version 0.81</li>
                   <li>VMware Virtual Disk Development Kit (VDDK) was updated to 7.0.3.4 to address  CVE-2023-38545.</li>
                   <li>Microsoft .NET 6.0.25 was updated to 6.0.29. </li>
                   <li>Microsoft WebView2 was updated to 123.0.2420.81. </li>
                   <li>PostgreSQL installer was updated to 15.6.1. </li>
                   <li>Curl was updated to 8.5.</li>
                   <li>Vulnerability&nbsp;<a href="https://www.veeam.com/kb4581" target="_blank" rel="noopener">CVE-2024-29849</a>&nbsp;in Veeam Backup Enterprise Manager was fixed.<br></li>
                   <li>Vulnerability&nbsp;<a href="https://www.veeam.com/kb4581" target="_blank" rel="noopener">CVE-2024-29850</a>&nbsp;in Veeam Backup Enterprise Manager was fixed.<br></li>
                   <li>Vulnerability&nbsp;<a href="https://www.veeam.com/kb4581" target="_blank" rel="noopener">CVE-2024-29851</a>&nbsp;in Veeam Backup Enterprise Manager was fixed.</li>
                   <li>Vulnerability&nbsp;<a href="https://www.veeam.com/kb4581" target="_blank" rel="noopener">CVE-2024-29852</a>&nbsp;in Veeam Backup Enterprise Manager was fixed.<br><br></li>
                  </ul>
                  <h4><b>12.1.1.56</b></h4>
                  <ul>
                   <li>PuTTY updated to version 0.80<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.1.0.2131</b></h4>
                  <ul>
                   <li>OpenSSL library updated to 1.0.2zi</li>
                   <li>LZ4 library updated to 1.9.4</li>
                   <li>curl updated to 8.0.1</li>
                   <li>Azure Identity package updated to 1.10.2</li>
                   <li>Stronger backup encryption <i>(see&nbsp;<a href="https://www.veeam.com/veeam_backup_12_1_whats_new_wn.pdf" target="_blank" rel="noopener">What's New in 12.1</a>&nbsp;p.7)</i></li>
                   <li>Enhanced protection for stored credentials<i>&nbsp;&nbsp;(see&nbsp;<a href="https://www.veeam.com/veeam_backup_12_1_whats_new_wn.pdf" target="_blank" rel="noopener">What's New in 12.1</a>&nbsp;p.7)<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>12.0.0.1420&nbsp;P20230412</b></h4>
                  <ul>
                   <li>OpenSSL Library updated to the newest version (1.0.2zg).<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>12.0.0.1420&nbsp;P20230223</b></h4>
                  <ul>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4424?ad=in-text-link" target="_blank" rel="noopener">CVE-2023-27532</a>) in Veeam Backup Service was fixed.<br><i>This vulnerability was reported by&nbsp;<a href="https://hackerone.com/shanigen?type=user" target="_blank" rel="noopener">Shanigen</a>.<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>12.0.0.1420</b></h4>
                  <ul>
                   <li>Added support for networks with NTLM authentication disabled (<a href="https://helpcenter.veeam.com/docs/backup/vsphere/kerberos_authentication.html?zoom_highlight=Kerberos-only&amp;ver=120" target="_blank" rel="noopener">Kerberos-only authentication</a>).</li>
                   <li>Added <a href="https://helpcenter.veeam.com/docs/backup/vsphere/best_practices_analyzer.html?ver=120" target="_blank" rel="noopener">Best Practices Analyzer</a> to check product configuration.</li>
                   <li><a href="https://helpcenter.veeam.com/docs/backup/em/audited_operations.html?ver=120" target="_blank" rel="noopener">Audit capabilities</a> were improved.</li>
                   <li>Added possibility to limit the number of logon sessions per user and to <a href="https://helpcenter.veeam.com/docs/backup/vsphere/users_roles.html" target="_blank" rel="noopener">log off users after an inactivity period</a></li>
                   <li>SMTP certificates validation was added for <a href="https://helpcenter.veeam.com/docs/backup/vsphere/general_email_notifications.html?ver=120" target="_blank" rel="noopener">email notifications</a></li>
                   <li>Network communication between CDP components is encrypted with TLS</li>
                   <li>Disabled insecure TLS protocols in communication with VMware infrastructure</li>
                   <li>zlib has been updated to version 1.2.13</li>
                   <li>OpenSSL version has been updated to 1.0.2ze</li>
                   <li>Putty has been updated to version 0.76<br><br></li>
                  </ul>
                  <h4><b>11.0.1.1261 P20240304</b></h4>
                  <ul>
                   <li>VMware Virtual Disk Development Kit (VDDK) was updated to 7.0.3.4.</li>
                   <li>OpenSSL was updated to v1.0.2zi.</li>
                   <li>liblz4 was updated to v1.9.4.</li>
                   <li>zlib was updated to v1.2.13.</li>
                   <li>PuTTY was updated to 0.80.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>11.0.1.1261&nbsp;P20230227</b></h4>
                  <ul>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4424" target="_blank" rel="noopener">CVE-2023-27532</a>) in Veeam Backup Service was fixed.<br><i>This vulnerability was reported by&nbsp;<a href="https://hackerone.com/shanigen?type=user" target="_blank" rel="noopener">Shanigen</a>.<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>11.0.1.1261 P20220302</b></h4>
                  <ul>
                   <li>Vulnerabilities (<a href="https://www.veeam.com/kb4288" target="_blank" rel="noopener">CVE-2022-26500</a>,&nbsp;<a href="https://www.veeam.com/kb4288" target="_blank" rel="noopener">CVE-2022-26501</a>) in Veeam Distribution Service were fixed.<br><i>These&nbsp;vulnerabilities were reported by Nikita Petrov (<a href="https://www.ptsecurity.com/" target="_blank" rel="noopener">Positive Technologies</a>).</i><br></li>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4290" target="_blank" rel="noopener">CVE-2022-26504</a>) in Veeam.Backup.PSManager was fixed.</li>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4289" target="_blank" rel="noopener">CVE-2022-26503</a>) in Veeam Agent&nbsp;<i>for Microsoft Windows</i> was fixed.<br><i>This vulnerability was reported by Nikita Petrov (<a href="https://www.ptsecurity.com/" target="_blank" rel="noopener">Positive Technologies</a>).<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>11.0.1.1261</b></h4>
                  <ul>
                   <li>Linux data mover: Added support for ECDHE TLS cipher suites; improved transport security.</li>
                   <li>Veeam Backup Enterprise Manager: hardened HTTP header configuration; disabled HTTP Trace method; restricted an ability to log into the Self-Service Restore Portal under NETWORK SERVICE accounts (the portal was dysfunctional for such logins).</li>
                   <li>Helper appliances: updated OpenVPN to version 2.4.11; updated OpenSSH to version 8.6.</li>
                   <li>Debug logs: Addressed issues which could result in sensitive information logged under certain circumstances.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>11.0.0.837 P20210507</b><br></h4>
                  <ul>
                   <li>Vulnerability (CVE-2021-35971) in the deserialization logic of Microsoft .NET remoting has been fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>11.0.0.837</b></h4>
                  <ul>
                   <li>.NET remoting communication security has been improved.<br></li>
                   <li>Data Mover communication protocol security has been improved.</li>
                   <li>Agent Management architecture security has been improved.</li>
                   <li>Veeam Explorers integration security has been improved</li>
                   <li>Veeam Backup Enterprise Manager Web App configuration and headers security has been improved.</li>
                   <li>Addressed issues which could cause sensitive information logged in certain circumstances.</li>
                   <li>Third-party libraries in FLR and SureBackup helper appliance have been updated to current versions.</li>
                   <li>Sustansys.Saml2 has been updated to version 2.7 to address known vulnerabilities.</li>
                   <li>LZ4 compression library version has been updated to version 1.9.2<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>10.0.1.4854&nbsp;P20220304</b></h4>
                  <ul>
                   <li>Vulnerabilities (<a href="https://www.veeam.com/kb4288" target="_blank" rel="noopener">CVE-2022-26500</a>,&nbsp;<a href="https://www.veeam.com/kb4288" target="_blank" rel="noopener">CVE-2022-26501</a>) in Veeam Distribution Service were fixed.<br><i>These&nbsp;vulnerabilities were reported by Nikita Petrov (<a href="https://www.ptsecurity.com/" target="_blank" rel="noopener">Positive Technologies</a>).</i><br></li>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4290" target="_blank" rel="noopener">CVE-2022-26504</a>) in Veeam.Backup.PSManager was fixed.</li>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4289" target="_blank" rel="noopener">CVE-2022-26503</a>) in Veeam Agent&nbsp;<i>for Microsoft Windows</i> was fixed.<br><i>This vulnerability was reported by Nikita Petrov (<a href="https://www.ptsecurity.com/" target="_blank" rel="noopener">Positive Technologies</a>).<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>10.0.1.4854 P20210609</b></h4>
                  <ul>
                   <li>Vulnerability (CVE-2021-35971) in the deserialization logic of Microsoft .NET remoting has been fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>10.0.1.4854</b><br></h4>
                  <ul>
                   <li>NAS Backup functionality can be used to gain unprivileged access to files on managed servers.</li>
                   <li>Weak credentials encryption issue in guest processing command line parameter and in PowerShell cmdlet logs.</li>
                   <li>Server and IIS version information is included in the response header of the Veeam Backup Enterprise Manager web app.</li>
                   <li>Security of Agent Management architecture has been improved.</li>
                   <li>Security of Cloud Connect architecture has been improved.</li>
                   <li>libcurl version has been updated to 7.70<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>10.0.0.4461</b></h4>
                  <ul>
                   <li>A custom security descriptor was provided for the driver's control device (vulnerability reported by Mile Karry).</li>
                   <li>Deserialization issues were fixed (vulnerability reported by Harrison Neal).</li>
                   <li>A user authorization issue was fixed (vulnerability reported by Harrison Neal).</li>
                   <li>Security of the Enterprise Manager Web App configuration was improved.</li>
                   <li>Support for weak SSH ciphers was disabled in the recovery media&nbsp;ISOs.</li>
                   <li>OpenSSL library was updated to version 1.0.2t</li>
                   <li>Putty was updated to version 0.73</li>
                   <li>Weak TLS ciphers were disabled in the Surebackup Linux appliance.</li>
                  </ul>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  As we're establishing this new process, we appreciate any feedback on the content or format of this KB article. Please let us know in the <a href="https://forums.veeam.com/vmware-vsphere-f24/include-security-fixes-in-release-notes-t56818.html" target="_blank" rel="noopener">corresponding topic</a> on the Veeam Community Forums. If your feedback is <a href="https://en.wikipedia.org/wiki/Responsible_disclosure" target="_blank" rel="noopener">too sensitive to be shared publicly</a>, please submit it by <a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">opening a support case</a>. We highly appreciate your collaboration!
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #ADACAF; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 13.0.1.1071]]></title>
 <link href="https://www.veeam.com/kb4792"/> 
 <id>https://www.veeam.com/kb4792</id>
 <updated>2026-01-06T00:00:00Z</updated>
 <published>2026-01-06T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[This article documents vulnerabilities found in Veeam Backup & Replication 13 that were resolved in build 13.0.1.1071. These vulnerabilities do not affect previous versions (i.e., 12.x and older).]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Vulnerabilities Resolved in Veeam Backup &amp; Replication 13.0.1.1071</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4792</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 13</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2026-01-06</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2026-01-06</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__text veeam-text">
               <p>All vulnerabilities documented in this article were resolved in <a href="https://www.veeam.com/kb4738" target="_blank" rel="noopener">Veeam Backup &amp; Replication 13.0.1.1071</a>.<br></p>
               <p><a href="https://www.veeam.com/products/downloads/latest-version.html" target="_blank" rel="noopener">Veeam Product Latest Version Download Page</a></p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-f5e9d7035d" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   All vulnerabilities disclosed in this article affect <b>Veeam Backup &amp; Replication&nbsp;13.0.1.180</b> and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 13 builds</a>. 
                   <br><sub><b>Note:&nbsp;</b>Previous versions of Veeam Backup &amp; Replication (i.e., 12.x and older) are <b><u>not</u></b> impacted by these vulnerabilities.</sub>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-55125</b></h4>
                   <p>This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.2<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source:</b> Discovered during internal testing.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-59468</b></h4>
                   <p>This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the <code>postgres</code> user by sending a malicious password parameter.</p>
                   <p><b>Severity:</b>&nbsp;Medium<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">6.7<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L</span></span><br><b>Source:</b> Discovered during internal testing.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-59469</b></h4>
                   <p>This vulnerability allows a Backup or Tape Operator to write files as root.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.2<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source:</b> Discovered during internal testing.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-59470</b></h4>
                   <p>This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as the <code>postgres</code> user by sending a malicious interval or order parameter.</p>
                   <p><b>Adjusted Severity*:</b>&nbsp;High<br><b>CVSS Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.0<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L</span></span><br><b>Source:</b> Discovered during internal testing.</p>
                   <p><b>*Reason for Adjustment:</b> The Backup and Tape Operator roles are considered highly privileged roles and should be protected as such. Following Veeam's recommended <a href="https://helpcenter.veeam.com/docs/vbr/userguide/security_guidelines.html?ver=13" target="_blank" rel="noopener">Security Guidelines</a>&nbsp;further reduces the opportunity for exploitability. Due to these factors affecting the temporal and environmental vectors of CVSS, Veeam has adjusted its response to this vulnerability to align with that of a High severity rating.</p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <p>These vulnerabilities were fixed starting with the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4738" target="_blank" rel="noopener">Veeam Backup &amp; Replication 13.0.1.1071</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[List of Security Fixes and Improvements in Veeam Agent for Microsoft Windows]]></title>
 <link href="https://www.veeam.com/kb3108"/> 
 <id>https://www.veeam.com/kb3108</id>
 <updated>2025-11-19T00:00:00Z</updated>
 <published>2025-11-19T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Agent for Microsoft Windows]]></name>
 </author>
 <summary><![CDATA[This article describes all security-related fixes and improvements introduced in each release or update of Veeam Agent for Microsoft Windows.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
  <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">List of Security Fixes and Improvements in&nbsp;Veeam Agent&nbsp;<i>for Microsoft Windows</i></h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
        <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">3108</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Agent&nbsp;<i>for Microsoft Windows</i> | 4.0 | 5.0 | 6.0 | 6.1 | 6.2 | 6.3 | 6.3.1 | 6.3.2 | 6.3.3 | 13</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2020-03-02</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-11-19</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
       <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Purpose</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>This article describes all security-related fixes and improvements introduced in each release or update of Veeam Agent&nbsp;<i>for Microsoft Windows</i>.</p>
                  <p>This article aims to provide our customers' security and compliance teams with detailed information on security improvements between releases to help them make an informed decision on whether it is critical to upgrade from their current Veeam Agent&nbsp;<i>for Microsoft Windows</i> version to a later one.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Security Fixes and Improvements</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <h4><b>13.0.1.120</b></h4>
                  <ul>
                   <li>OpenSSL upgraded to version 3.0.17<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>13.0.0.835</b></h4>
                  <ul>
                   <li>Communication protocol was switched to gRPC</li>
                   <li>OpenSSL upgraded to version 3.0.8</li>
                   <li>System.IdentityModel.Tokens.Jwt upgraded to version 8.0.2</li>
                  </ul>
                  <p>&nbsp;</p>
                  <h4><b>6.3.2.1302</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4771" target="_blank" rel="noopener">CVE-2025-48982</a> vulnerability was fixed.</li>
                  </ul>
                  <h4>&nbsp;</h4>
                  <h4><b>6.3.2.1205</b></h4>
                  <ul>
                   <li><a href="https://www.veeam.com/kb4743" target="_blank" rel="noopener">CVE-2025-24287</a>&nbsp;vulnerability was fixed.</li>
                  </ul>
                  <p>&nbsp;</p>
                  <h4><b>6.3.0.177</b></h4>
                  <ul>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4693" target="_blank" rel="noopener">CVE-2024-45207</a>)&nbsp;in Veeam Agent for Microsoft Windows was fixed.</li>
                  </ul>
                  <p>&nbsp;</p>
                  <h4><b>6.1.2.134</b></h4>
                  <ul>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4582" target="_blank" rel="noopener">CVE-2024-29853</a>)&nbsp;in Veeam Agent for Microsoft Windows was fixed.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>6.1.0.349</b></h4>
                  <ul>
                   <li>OpenSSL library updated to 1.0.2zi.</li>
                   <li>LZ4 library updated to 1.9.4.</li>
                   <li>Stronger backup encryption. -&nbsp;<i>(See pg. 7 of&nbsp;<a href="https://www.veeam.com/veeam_backup_12_1_whats_new_wn.pdf" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.1 What's New PDF</a>)<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>6.0.2.1090</b></h4>
                  <ul>
                   <li>OpenSSL Library updated to the newest version (1.0.2zg).<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>6.0.0.960</b></h4>
                  <ul>
                   <li>Added support for networks with NTLM authentication disabled (<a href="https://helpcenter.veeam.com/docs/backup/vsphere/kerberos_authentication.html?zoom_highlight=Kerberos-only&amp;ver=120" target="_blank" rel="noopener">Kerberos-only authentication</a>).</li>
                   <li>Audit capabilities were improved.</li>
                   <li>zlib has been updated to version 1.2.13.</li>
                   <li>OpenSSL version has been updated to 1.0.2ze.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>5.0.3.5029</b></h4>
                  <ul>
                   <li>OpenSSL was updated to v1.0.2zi.</li>
                   <li>liblz4 was updated to v1.9.4.</li>
                   <li>zlib was updated to v1.2.13.</li>
                   <li>PuTTY was updated to 0.80.<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>5.0.3.4708</b></h4>
                  <ul>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4289" target="_blank" rel="noopener">CVE-2022-26503</a>) in Veeam Agent&nbsp;<i>for Microsoft Windows</i> was fixed.<br><i>This vulnerability was reported by Nikita Petrov (<a href="https://www.ptsecurity.com/" target="_blank" rel="noopener">Positive Technologies</a>).<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>5.0.0.4301</b></h4>
                  <ul>
                   <li>LZ4 compression library version has been updated to version 1.9.2<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>4.0.2.2208</b></h4>
                  <ul>
                   <li>Vulnerability (<a href="https://www.veeam.com/kb4289" target="_blank" rel="noopener">CVE-2022-26503</a>) in Veeam Agent&nbsp;<i>for Microsoft Windows</i> was fixed.<br><i>This vulnerability was reported by Nikita Petrov (<a href="https://www.ptsecurity.com/" target="_blank" rel="noopener">Positive Technologies</a>).<br>
                      &nbsp;</i></li>
                  </ul>
                  <h4><b>4.0.0.1811</b></h4>
                  <ul>
                   <li>A custom security descriptor was provided for the driver's control device (vulnerability reported by Mile Karry).</li>
                   <li>Deserialization issues were fixed (vulnerability reported by Harrison Neal).</li>
                   <li>A user authorization issue was fixed (vulnerability reported by Harrison Neal).</li>
                   <li>OpenSSL was updated to version 1.0.2t</li>
                  </ul>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section section--round-corners-big   " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  As we're establishing this new process, we appreciate any feedback on the content or format of this KB article. Please let us know in the <a href="https://forums.veeam.com/vmware-vsphere-f24/include-security-fixes-in-release-notes-t56818.html" target="_blank" rel="noopener">related topic</a> on the Veeam R&amp;D Forums. If your feedback is <a href="https://en.wikipedia.org/wiki/Responsible_disclosure" target="_blank" rel="noopener">too sensitive to be shared publicly</a>, please submit it by <a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">opening a support case</a>. We highly appreciate your collaboration!
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #ADACAF; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4165 Patch]]></title>
 <link href="https://www.veeam.com/kb4771"/> 
 <id>https://www.veeam.com/kb4771</id>
 <updated>2025-10-14T00:00:00Z</updated>
 <published>2025-10-14T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2.4165 Patch]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Vulnerabilities Resolved in Veeam Backup &amp; Replication 12.3.2.4165 Patch</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4771</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2025-10-14</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-10-15</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__text veeam-text">
               <p>All vulnerabilities documented in this article were resolved in <a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2.4165 Patch</a>.<br></p>
               <p><a href="https://www.veeam.com/products/downloads/latest-version.html" target="_blank" rel="noopener">Veeam Product Latest Version Download Page</a></p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-5647323c13" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-48983</b></h4>
                   <p>A vulnerability in the Mount service of Veeam Backup &amp; Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Reported by CODE WHITE.</p>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--md" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     <b>Note:&nbsp;</b>This vulnerability only impacts domain-joined&nbsp;<a href="https://helpcenter.veeam.com/docs/backup/vsphere/add_windows_server.html" target="_blank" rel="noopener">backup infrastructure servers</a>&nbsp;added to Veeam Backup &amp; Replication v12.&nbsp;Backup infrastructure servers that are not domain-joined are not impacted by this vulnerability.
                     <br><a href="https://bp.veeam.com/security/Design-and-implementation/Hardening/Workgroup_or_Domain.html#best-practice" target="_blank" rel="noopener"><sup>Veeam Backup &amp; Replication Security Best Practice Guide &gt; Workgroup or Domain?</sup></a>
                     <br>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Backup &amp; Replication 12.3.2.3617 and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.</sub></p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--md" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     <b>Note:&nbsp;</b>The Veeam Software Appliance and upcoming Veeam Backup &amp; Replication v13 software for Microsoft Windows are architecturally not impacted by these types of vulnerabilities.
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h5><b>Solution</b></h5>
                   <p>This vulnerability was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2.4165 Patch</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-48984</b></h4>
                   <p>A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b> <span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">&gt;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Reported by&nbsp;Sina Kheirkhah (@SinSinology) and Piotr Bazydlo (@chudyPB) of watchTowr.</p>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--md" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     <b>Note:&nbsp;</b>This vulnerability only impacts domain-joined Veeam Backup &amp; Replication v12&nbsp;backup servers. Backup servers that are not domain-joined are not impacted by this vulnerability.
                     <br><a href="https://bp.veeam.com/security/Design-and-implementation/Hardening/Workgroup_or_Domain.html#best-practice" target="_blank" rel="noopener"><sup>Veeam Backup &amp; Replication Security Best Practice Guide &gt; Workgroup or Domain?</sup></a>
                     <br>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Backup &amp; Replication 12.3.2.3617 and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.</sub></p>
                   <ul>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--md" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     <b>Note:&nbsp;</b>The Veeam Software Appliance and upcoming Veeam Backup &amp; Replication v13 software for Microsoft Windows are architecturally not impacted by these types of vulnerabilities.
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h5><b>Solution</b></h5>
                   <p>This vulnerability was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2.4165 Patch</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-48982</b></h4>
                   <p>This vulnerability in Veeam Agent&nbsp;<i>for Microsoft Windows</i> allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.3<span class="veeam-tooltip-text">CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</span></span><br><b>Source: </b>Reported by an anonymous contributor working with the Trend Zero Day Initiative.</p>
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Agent&nbsp;<i>for Microsoft Windows</i>&nbsp;6.3.2.1205 and all&nbsp;<a href="https://www.veeam.com/kb2683" target="_blank" rel="noopener">earlier version 6 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.<br></sub></p>
                   <h5><b>Solution</b></h5>
                   <p>This vulnerability was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb2683" target="_blank" rel="noopener">Veeam Agent&nbsp;<i>for Microsoft Windows</i> 6.3.2.1302</a><br><sup>Veeam Agent&nbsp;<i>for Microsoft Windows</i> is included with Veeam Backup &amp; Replication and available as a standalone application.</sup></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[List of Security Fixes and Improvements in Veeam Backup for Nutanix AHV]]></title>
 <link href="https://www.veeam.com/kb4236"/> 
 <id>https://www.veeam.com/kb4236</id>
 <updated>2025-09-03T00:00:00Z</updated>
 <published>2025-09-03T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup for Nutanix AHV]]></name>
 </author>
 <summary><![CDATA[List of Security Fixes and Improvements in Veeam Backup for Nutanix AHV]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
  <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">List of Security Fixes and Improvements in Veeam Backup <i>for Nutanix AHV</i></h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
        <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4236</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup <i>for Nutanix AHV</i> | 2.1 | 3.0 | 4.0 | 5.0 | 5.1 | 6 | 6.1 | 7 | 9</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2021-11-03</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-09-03</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
       <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Purpose</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>This article describes all security-related fixes and improvements introduced in each release or update of Veeam Backup <i>for Nutanix AHV</i>.</p>
                  <p>This article aims to provide our customers' security and compliance teams with detailed information on security improvements between releases to help them decide whether it is critical to upgrade from their current Veeam Backup <i>for Nutanix AHV</i> version to a later one.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Security Fixes and Improvements</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <h4><b>Veeam Plug-in for Nutanix AHV 13.8&nbsp; (Veeam Backup <i>for Nutanix AHV</i> 8)</b></h4>
                  <ul>
                   <li>system.linq.dynamic.core was updated to version 1.6.0.2<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>Veeam Backup <i>for Nutanix AHV</i> 6</b></h4>
                  <ul>
                   <li>@microsoft/signalr/ws was updated to version 7.5.10</li>
                   <li>@microsoft/signalr was updated to version 6.0.25</li>
                   <li>Microsoft.EntityFrameworkCore was updated to version 8.0.5</li>
                   <li>Npgsql.EntityFrameworkCore.PostgreSQL was updated to version 8.0.4</li>
                   <li>Microsoft.Identity.Client was updated to version 4.60.3</li>
                   <li>Azure.Identity was updated to version 1.11.0</li>
                   <li>Google.Protobuf was updated to version 3.15.0</li>
                   <li>Google.Protobuf.Tools was updated to version 3.15.0<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>Veeam Backup <i>for Nutanix AHV</i> 5.1</b></h4>
                  <ul>
                   <li>AHV Proxy OS was upgraded to Ubuntu 22.04</li>
                   <li>traverse library was updated to 7.23.2</li>
                   <li>tough-cookie was updated to 4.1.3</li>
                   <li>System.Linq.Dynamic.Core was updated to 1.3.3<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>Veeam Backup <i>for Nutanix AHV</i> 4a</b></h4>
                  <ul>
                   <li>Upgraded OpenSSL to version 1.0.2zg<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>Veeam Backup <i>for Nutanix AHV</i> 4</b></h4>
                  <ul>
                   <li>AHV Proxy OS upgraded to Ubuntu 20.04</li>
                   <li>.NET Core updated to version 6</li>
                   <li>3rd party components were updated</li>
                   <li>Added brute-force protection to REST API</li>
                   <li>Web App configuration has been improved, strict-transport-security header has been added</li>
                   <li>SMTP certificate validation added for email notifications</li>
                   <li>Newtonsoft.Json library has been updated to version 13.0.1</li>
                   <li>Google.Protobuf library has been updated to version 3.21.9<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>Veeam Backup <i>for Nutanix AHV</i> 3</b></h4>
                  <ul>
                   <li>AHV Proxy OS upgraded to Ubuntu 18.04</li>
                   <li>.NET Core&nbsp;updated to version&nbsp;3.1<br>
                     &nbsp;</li>
                  </ul>
                  <h4><b>Veeam Backup <i>for Nutanix AHV</i> 2.1</b></h4>
                  <ul>
                   <li>AHV Backup Proxy no longer uses the following unsafe TLS ciphers: 
                    <ul>
                     <li>TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA</li>
                     <li>TLS_ECDH_anon_WITH_AES_128_CBC_SHA</li>
                     <li>TLS_ECDH_anon_WITH_AES_256_CBC_SHA</li>
                     <li>TLS_ECDH_anon_WITH_RC4_128_SHA</li>
                    </ul></li>
                  </ul>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  As we're establishing this new process, we appreciate any feedback on the content or format of this KB article. Please let us know in the&nbsp;<a href="https://forums.veeam.com/vmware-vsphere-f24/include-security-fixes-in-release-notes-t56818.html" target="_blank" rel="noopener">corresponding topic</a>&nbsp;on the Veeam Community Forums. If your feedback is&nbsp;<a href="https://en.wikipedia.org/wiki/Responsible_disclosure" target="_blank" rel="noopener">too sensitive to be shared publicly</a>, please submit it by&nbsp;<a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">opening a support case</a>. We highly appreciate your collaboration!
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #ADACAF; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2]]></title>
 <link href="https://www.veeam.com/kb4743"/> 
 <id>https://www.veeam.com/kb4743</id>
 <updated>2025-06-17T00:00:00Z</updated>
 <published>2025-06-17T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3.2]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title center 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Vulnerabilities Resolved in Veeam Backup &amp; Replication 12.3.2</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4743</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1<br>
                  Veeam Agent&nbsp;<i>for Microsoft Windows</i> | 6.0 | 6.1 | 6.2 | 6.3 | 6.3.1</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2025-06-17</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-07-24</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__text veeam-text">
               <p>All vulnerabilities documented in this article were resolved in <a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2</a>.<br></p>
               <p><a href="https://www.veeam.com/products/downloads/latest-version.html" target="_blank" rel="noopener">Veeam Product Latest Version Download Page</a></p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-9711361687" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-23121</b></h4>
                   <p>A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.0 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Reported Piotr Bazydlo (@chudyPB) of <a href="https://watchtowr.com/" target="_blank" rel="noopener">watchTowr</a> and CodeWhite.</p>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--ss" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     <b>Note:&nbsp;</b>This vulnerability only impacts domain-joined backup servers.
                     <br><a href="https://bp.veeam.com/security/Design-and-implementation/Hardening/Workgroup_or_Domain.html#best-practice" target="_blank" rel="noopener"><sup>Veeam Backup &amp; Replication Security Best Practice Guide &gt; Workgroup or Domain?</sup></a>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Backup &amp; Replication 12.3.1.1139 and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.<br></sub></p>
                   <h5><b>Solution</b></h5>
                   <p>This vulnerability was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2 (build 12.3.2.3617)</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-24286</b></h4>
                   <p>A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute arbitrary code.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.2<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source: </b>Reported by Nikolai Skliarenko with Trend Micro.</p>
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Backup &amp; Replication 12.3.1.1139 and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.<br></sub></p>
                   <h5><b>Solution</b></h5>
                   <p>This vulnerability was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3.2 (build 12.3.2.3617)</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-24287</b></h4>
                   <p>A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.</p>
                   <p><b>Severity:</b>&nbsp;Medium<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">6.1<span class="veeam-tooltip-text">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L</span></span><br><b>Source: </b>Reported by an anonymous contributor working with the Trend Zero Day Initiative.</p>
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Agent&nbsp;<i>for Microsoft Windows</i> 6.3.1.1074 and all&nbsp;<a href="https://www.veeam.com/kb2683" target="_blank" rel="noopener">earlier version 6 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.<br></sub></p>
                   <h5><b>Solution</b></h5>
                   <p>This vulnerability was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb2683" target="_blank" rel="noopener">Veeam Agent&nbsp;<i>for Microsoft Windows</i> 6.3.2 (build 6.3.2.1205)</a><br><sup>Veeam Agent&nbsp;<i>for Microsoft Windows</i> is included with Veeam Backup &amp; Replication and available as a standalone application.</sup></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[CVE-2025-23120]]></title>
 <link href="https://www.veeam.com/kb4724"/> 
 <id>https://www.veeam.com/kb4724</id>
 <updated>2025-03-19T00:00:00Z</updated>
 <published>2025-03-19T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[CVE-2025-23120]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">CVE-2025-23120</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4724</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 12 | 12.1 | 12.2 | 12.3</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2025-03-19</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-03-24</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-47d81cfe9c" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-23120</b></h4>
                   <p>A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.<br></p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source:</b>&nbsp;Reported by Piotr Bazydlo of <a href="https://watchtowr.com/" title="https://watchtowr.com/" target="_blank" rel="noopener">watchTowr</a>.</p>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     <b>Note:&nbsp;</b>This vulnerability only impacts domain-joined backup servers.
                     <br>
                     <br><a href="https://bp.veeam.com/security/Design-and-implementation/Hardening/Workgroup_or_Domain.html#best-practice" target="_blank" rel="noopener"><sup>Veeam Backup &amp; Replication Security Best Practice Guide &gt; Workgroup or Domain?</sup></a>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h5><b>Affected Product</b></h5>
                   <p>Veeam Backup &amp; Replication 12.3.0.310 and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>.<br><sub><b>Note:&nbsp;</b><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.</sub></p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   The vulnerability documented in this section was fixed starting in the following build:
                  </div>
                 </div>
                </div>
                <div class="resource-list-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="resource-list ">
                   <ul class="resource-list__container resource-list__container--column">
                    <li class="resource-list__item"><a class="resource-list__link" href="https://www.veeam.com/kb4696" target="_self"> <i class="resource-list__icon fa-solid fa-up-right-from-square"></i>Veeam Backup &amp; Replication 12.3.1 <i>(build 12.3.1.1139)</i> </a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   Upgrading to Veeam Backup &amp; Replication 12.3.1 is the recommended way to mitigate this vulnerability. Please click the link above to review the Release Information for Veeam Backup &amp; Replication 12.3.1, download links for the upgrade and update ISOs are provided in the above-linked KB article.
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="expander-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="expander  " data-component="ExpanderComponent" data-config="{
            &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
            &quot;eventLabel&quot;: &quot;Vulnerability Hotfix for Veeam Backup &amp; Replication 12.3&quot;,
            &quot;eventCategory&quot;: &quot;&quot;
         }">
                  <details class="expander__container expander__container--hide-borders">
                   <summary class="expander__title"> <span> Vulnerability Hotfix for Veeam Backup &amp; Replication 12.3 </span> </summary>
                   <div class="expander__content">
                    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                     <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                      <div class=" veeam-component__component-spacing-below--md">
                       <div class="veeam-text  " data-component="VeeamTextComponent">
                        <p>For existing deployments of Veeam Backup &amp; Replication 12.3 (build 12.3.0.310), a hotfix to resolve this vulnerability has been developed and is intended for customers who cannot immediately <a href="https://www.veeam.com/kb4696#upiso" target="_blank" rel="noopener">update to version 12.3.1</a>.</p>
                        <p><i>For deployments operating of Veeam Backup &amp; Replication <u><b>lower than 12.3.0.310</b></u>,&nbsp;please&nbsp;<a href="https://helpcenter.veeam.com/docs/backup/vsphere/upgrade_vbr.html?ver=120" target="_blank" rel="noopener">upgrade</a>&nbsp;directly to <a href="https://www.veeam.com/kb4696#iso" target="_blank" rel="noopener">version 12.3.1</a>.</i></p>
                        <p><b><span class="text-color-error">Note:</span></b> This hotfix can only be installed if Veeam Backup &amp; Replication 12.3 has <b>no other hotfixes installed</b>, as it may overwrite earlier hotfixes. If other hotfixes for version 12.3 have been installed, the deployment must be <a href="https://www.veeam.com/kb4696#upiso" target="_blank" rel="noopener">updated to 12.3.1</a>.</p>
                       </div>
                      </div>
                     </div>
                     <div class="universal-button-component aem-GridColumn aem-GridColumn--default--12">
                      <div class=" veeam-component__component-spacing-below--md">
                       <div class="universal-button   " data-component="UniversalButtonComponent" data-config="{
        &quot;ctaLink&quot;: &quot;https://www.veeam.com/download_add_packs/vmware-esx-backup/12.3.0.310_CVE_Hotfix/&quot;,
        &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
        &quot;eventCategory&quot;: &quot;&quot;,
        &quot;eventAction&quot;: &quot;&quot;,
        &quot;eventLabel&quot;: &quot;Download button - en&quot;,
        &quot;openPopup&quot;: false,
        &quot;sticky&quot;: false
     }">
                        <div class="universal-button__container">
                         <a href="https://www.veeam.com/download_add_packs/vmware-esx-backup/12.3.0.310_CVE_Hotfix/" aria-label="Download button - en" class="universal-button__button universal-button__button--secondary universal-button__button--text-center "> <span class="universal-button__label">download hotfix for 12.3</span></a>
                         <div class="universal-button__description">
                          <p></p>
                          <p style="text-align: left;"><span class="text-color-error"><b><sup>This hotfix is only compatible with Veeam Backup &amp; Replication 12.3<i> (build 12.3.0.310)</i>.</sup></b></span></p>
                          <p style="text-align: left;"><b>Filename:</b>&nbsp;VeeamBackup&amp;Replication_12.3.0.310_KB4724.zip<br><b>MD5:</b>&nbsp;<code>5185235DEA2AC9F2814638534B16A6DB<br></code><b>SHA1:&nbsp;</b><code>4B1C3A7F2F051D958EAF363E2739B1B38C4A4F8C</code></p>
                          <p></p>
                         </div>
                        </div>
                       </div>
                      </div>
                     </div>
                     <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                      <div class=" veeam-component__component-spacing-below--ss">
                       <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                        <p><b>This hotfix does not change the build number of the software.&nbsp;</b>To validate that the hotfix has been deployed, compare the hash value of the files present on the system with the known hash value of the hotfix files.</p>
                        <ul>
                         <li><b>Veeam.Backup.Common.dll</b> — SHA1: <code>F81B62807D82D9648733B1BF5AD70172B6CB19AA</code></li>
                         <li><b>Veeam.Backup.EsxManager.dll</b> — SHA1: <code>9D72DD7E5CBE920454E7508AAF328CD1A59197E0</code></li>
                        </ul>
                        <p>The following PowerShell commands can be used to check the SHA1 hash value of a given file.<br><sub><b>Note: </b>These commands check the dll in its default location, the path may need to adjusted if Veeam Backup &amp; Replication was installed to a different drive or folder.</sub></p>
                       </div>
                      </div>
                     </div>
                     <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                      <div class="code-block  veeam-component__component-spacing-below--ss" data-component="CodeBlockComponent">
                       <div class="code-toolbar">
                        <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token function">Get-FileHash</span> <span class="token operator">-</span>Path <span class="token string">'C:\Program Files\Veeam\Backup and Replication\Backup\Veeam.Backup.Common.dll'</span> <span class="token operator">-</span>Algorithm SHA1<span class="line-numbers-rows"><span></span></span></code></pre>
                        <div class="toolbar">
                         <div class="toolbar-item">
                          <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                         </div>
                        </div>
                       </div>
                      </div>
                     </div>
                     <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                      <div class="code-block  veeam-component__component-spacing-below--md" data-component="CodeBlockComponent">
                       <div class="code-toolbar">
                        <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token function">Get-FileHash</span> <span class="token operator">-</span>Path <span class="token string">'C:\Program Files\Veeam\Backup and Replication\Backup\Veeam.Backup.EsxManager.dll'</span> <span class="token operator">-</span>Algorithm SHA1<span class="line-numbers-rows"><span></span></span></code></pre>
                        <div class="toolbar">
                         <div class="toolbar-item">
                          <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                         </div>
                        </div>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                  </details>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[CVE-2025-23114]]></title>
 <link href="https://www.veeam.com/kb4712"/> 
 <id>https://www.veeam.com/kb4712</id>
 <updated>2025-02-04T00:00:00Z</updated>
 <published>2025-02-04T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup for Salesforce]]></name>
 </author>
 <summary><![CDATA[A vulnerability impacting the Veeam Updater component used by the proxy appliance within Veeam Backup for AWS, Veeam Backup for Google Cloud, Veeam Backup for Microsoft Azure, Veeam Backup for Nutanix AHV, Oracle Linux Virtualization Manager and Red Hat Virtualization, Veeam Backup for Salesforce]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title"><b>CVE-2025-23114</b></h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4712</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup <i>for Salesforce</i><br>
                  Veeam Backup <i>for Nutanix AHV</i><br>
                  Veeam Backup <i>for AWS</i><br>
                  Veeam Backup <i>for Microsoft Azure</i><br>
                  Veeam Backup <i>for Google Cloud</i><br>
                  Veeam Backup <i>for Oracle Linux Virtualization Manager and Red Hat Virtualization</i></td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2025-02-04</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-02-14</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-99971e0386" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__title">
               Automatic Updates
              </div>
              <div class="notice__text veeam-text">
               <p>The vulnerability discussed in this article affects the Veeam Updater component within the backup appliances used by the listed applications. The updated version of this Veeam Updater component will have been published to the <a href="https://repository.veeam.com/" target="_blank" rel="noopener">Veeam Repository</a> alongside the release of this announcement.<b> As automatic updates are enabled for all backup appliances associated with this issue, all actively supported backup appliance versions will automatically download and install this updated version of the Veeam Updater component.</b></p>
               <p>Furthermore, for all applications other than Veeam Backup for Salesforce, the latest version of each appliance discussed in this article is unaffected by this vulnerability. This means that customers whose Veeam Backup &amp; Replication deployments utilize these backup appliances are unaffected if they have already upgraded to version 12.3 and updated those backup appliances.</p>
               <p><b>Note:</b> Customers who do not use any of the applications listed in the Issue Details section are entirely unaffected by this vulnerability. For information about checking whether such backup appliances are managed by Veeam Backup &amp; Replication, please refer to the <a href="#moreinfo" target="_self">More Information</a> section.</p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h3><b>CVE-2025-23114</b></h3>
                   <p>A vulnerability within the Veeam Updater component that allows an attacker to utilize a Man-in-the-Middle attack to execute arbitrary code on the affected appliance server with root-level permissions.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b> <span class="veeam-tooltip">9.0<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source:</b>&nbsp;&nbsp;Reported by <a href="https://hackerone.com/putsi?type=user" target="_blank" rel="noopener">@putsi</a> via HackerOne.<br>
                     &nbsp;</p>
                   <h4><b>Affected Products</b></h4>
                   <h5><b>Current Releases</b></h5>
                   <p>The following product's&nbsp;<b>current</b> release is affected by this vulnerability:</p>
                   <ul>
                    <li>Veeam Backup <i>for Salesforce</i> — 3.1 and older<br>
                      &nbsp;</li>
                   </ul>
                   <h5><b>Previous Releases</b></h5>
                   <p>The following product's&nbsp;<b>older </b>releases utilize an older Veeam Updater component that was also found to be affected.<br><sup>As noted below each entry, the most recent version of each of these appliances is&nbsp;<b>not affected</b>. Therefore, if Veeam Backup &amp; Replication is running version 12.3, and the appliances for these applications have been updated, they will be running a current and unaffected version.</sup></p>
                   <ul>
                    <li>Veeam Backup <i>for Nutanix AHV</i>&nbsp;— 5.0 | 5.1<br><sup>Note: Version 6 (released on 2024-08-24 alongside VBR 12.2) and higher are unaffected by this vulnerability.</sup></li>
                    <li>Veeam Backup <i>for AWS</i> — 6a |&nbsp; 7<br><sup>Note: The most recent version (v8), released on 2024-07-02, is unaffected by this vulnerability.</sup></li>
                    <li>Veeam Backup <i>for Microsoft Azure</i> — 5a | 6<br><sup>Note: The most recent version (v7), released on 2024-07-02, is unaffected by this vulnerability.</sup></li>
                    <li>Veeam Backup <i>for Google Cloud</i> — 4 | 5<br><sup>Note: The most recent version (v6), released on 2024-12-03, is unaffected by this vulnerability.</sup></li>
                    <li>&nbsp;Veeam Backup <i>for Oracle Linux Virtualization Manager and Red Hat Virtualization</i>&nbsp;— 3 | 4.0 | 4.1<br><sup>Note: Version 5 (released on 2024-08-24 alongside VBR 12.2) and higher are unaffected by this vulnerability.</sup></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Veeam Backup <i>for Salesforce</i></b></h4>
                   <p>The vulnerability was resolved in Veeam Updater component version 9.0.0.1124.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/backup_salesforce/userguide/updates_check.html?ver=30" target="_blank" rel="noopener">Checking for Updates</a>&nbsp;using the built-in Veeam Updater to update the Veeam Updater component.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/backup_salesforce/userguide/updates_history.html?ver=30" target="_blank" rel="noopener">View updates history</a>, and check the Veeam Updater version shown in the top-right corner.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Veeam Backup <i>for Nutanix AHV</i></b></h4>
                   <p><sup><b>Note:&nbsp;</b>If Veeam Backup &amp; Replication 12.3 is installed, and the&nbsp;Veeam Backup <i>for Nutanix AHV</i> appliance has already been <a href="https://helpcenter.veeam.com/docs/vbahv/userguide/upgrading_vbahv.html?ver=7" target="_blank" rel="noopener">upgraded</a>, the appliance is unaffected by this vulnerability.</sup></p>
                   <p>The vulnerability was resolved in Veeam Updater component version&nbsp;9.0.0.1125.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbahv/userguide/update_check.html?ver=7" target="_blank" rel="noopener">Checking for Updates</a>&nbsp;using the built-in Veeam Updater to update the Veeam Updater component.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbahv/userguide/updates_history.html?ver=7" target="_blank" rel="noopener">View updates history</a>, and check the Veeam Updater version shown in the top-right corner.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Veeam Backup <i>for AWS</i></b></h4>
                   <p><sup><b>Note:&nbsp;</b>If Veeam Backup &amp; Replication 12.3 is installed, and the&nbsp;<b>AWS backup appliance</b> has already been <a href="https://helpcenter.veeam.com/docs/vbaws/guide/upgrade_appliance_console.html?ver=80" target="_blank" rel="noopener">upgraded</a>, the appliance is unaffected by this vulnerability.</sup></p>
                   <p>The vulnerability was resolved in Veeam Updater component version&nbsp;9.0.0.1126.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbaws/guide/updates_check.html" target="_blank" rel="noopener">Checking for Updates</a>&nbsp;using the built-in Veeam Updater to update the Veeam Updater component.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbaws/guide/updates_history.html?ver=80" target="_blank" rel="noopener">View updates history</a>, and check the Veeam Updater version shown in the top-right corner.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Veeam Backup <i>for Microsoft Azure</i></b></h4>
                   <p><sup><b>Note:</b>&nbsp;If Veeam Backup &amp; Replication 12.3 is installed, and the&nbsp;<b>Microsoft Azure backup appliance</b> has already been <a href="https://helpcenter.veeam.com/docs/vbazure/guide/updating_console.html?ver=70" target="_blank" rel="noopener">upgraded</a>, the appliance is unaffected by this vulnerability.</sup></p>
                   <p>The vulnerability was resolved in Veeam Updater component version&nbsp;9.0.0.1128.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbazure/guide/updates_check.html?ver=70" target="_blank" rel="noopener">Checking for Updates</a>&nbsp;using the built-in Veeam Updater to update the Veeam Updater component.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbazure/guide/update_history.html?ver=70" target="_blank" rel="noopener">View updates history</a>, and check the Veeam Updater version shown in the top-right corner.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Veeam Backup <i>for Google Cloud</i></b></h4>
                   <p><sup><b>Note:</b>&nbsp;If Veeam Backup &amp; Replication 12.3 is installed, and the&nbsp;<b>Google Cloud backup appliance</b> has already been <a href="https://helpcenter.veeam.com/docs/vbgc/guide/appliance_upgrade_console.html?ver=6" target="_blank" rel="noopener">upgraded</a>, the appliance is unaffected by this vulnerability.</sup></p>
                   <p>The vulnerability was resolved in Veeam Updater component version&nbsp;9.0.0.1126.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbgc/guide/updates_check.html" target="_blank" rel="noopener">Checking for Updates</a>&nbsp;using the built-in Veeam Updater to update the Veeam Updater component.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbazure/guide/update_history.html?ver=70" target="_blank" rel="noopener">View updates history</a>, and check the Veeam Updater version shown in the top-right corner.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Veeam Backup <i>for Oracle Linux Virtualization Manager and Red Hat Virtualization</i></b></h4>
                   <p><sup><b>Note: </b>If Veeam Backup &amp; Replication 12.3 is installed, and the&nbsp;Veeam Backup <i>for Oracle Linux Virtualization Manager and Red Hat Virtualization</i> appliance has already been <a href="https://helpcenter.veeam.com/docs/vbrhv/userguide/upgrading.html?ver=6" target="_blank" rel="noopener">upgraded</a>, the appliance is unaffected by this vulnerability.</sup></p>
                   <p>The vulnerability was resolved in Veeam Updater component version 9.0.0.1127.<br>
                     All Veeam Updater component versions equal to or higher than this are unaffected by this vulnerability.</p>
                   <p><a href="https://helpcenter.veeam.com/docs/vbrhv/userguide/updates.html?ver=6" target="_blank" rel="noopener">Update the backup appliance</a>&nbsp;from within the Veeam Backup &amp; Replication Console.</p>
                   <p>To check which Veeam Updater component is used by the Veeam Backup <i>for Oracle Linux Virtualization Manager and Red Hat Virtualization</i> appliance:</p>
                   <ol>
                    <li><a href="https://helpcenter.veeam.com/docs/vbrhv/userguide/export_logs.html?ver=6#downloading-logs" target="_blank" rel="noopener">Download support logs from the appliance</a>.</li>
                    <li>Within the collected logs, open the file "<code>&lt;log_bundle&gt;/veeam/veeam-updater/updater.log</code>"</li>
                    <li>Review the logs to identify the Veeam Updater component version. In most cases, the version will be listed in the lines just after a reference to the service <code>Starting</code>. 
                     <ul>
                      <li>For newer unaffected appliance versions (v5 and higher), the entry will appear as "<code>Application&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;:&nbsp; Veeam.Updater, Version=</code>".<br>
                        For example: 
                       <pre>&nbsp;<b>Starting</b> log. Severity threshold: Information, LogFilesNumber = 10, LogFileMaxSize = 10 Mbs, ArchivesLimit = 10
-----------------------------------------------------------------------------------------------------------------
Release version&nbsp; &nbsp; &nbsp; &nbsp;:&nbsp; <b>11.0.0.754</b>
Application&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;:&nbsp; Veeam.Updater, Version=<b>11.0.0.754</b>, Culture=neutral, PublicKeyToken=null
</pre></li>
                      <li>For older <b>affected</b> appliance versions (v3, v4, and v4.1), the entry will appear as "<code>Main.main: Version:</code>"<br>
                        For example: 
                       <pre>MM.DD.YYYY HH:MM:SS [info&nbsp; &nbsp; ] ### [###] Main.main: ============= <b>Starting</b> =============
MM.DD.YYYY HH:MM:SS [info&nbsp; &nbsp; ] ### [###]&nbsp;Main.main: Version: <b>9.0.0.1087</b>
</pre> In this example the Veeam Updater build is less than the fixed build (9.0.0.1127) and would indicate that <a href="https://helpcenter.veeam.com/docs/vbrhv/userguide/updates.html?ver=6" target="_blank" rel="noopener">the Veeam Backup <i>for Oracle Linux Virtualization Manager and Red Hat Virtualization</i> backup appliance needs to be updated</a>.</li>
                     </ul></li>
                   </ol>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                 <span class="anchor" id="moreinfo"></span>
                </div>
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>If a Veeam Backup &amp; Replication deployment is&nbsp;<b>not protecting</b>&nbsp;AWS, Google Cloud, Microsoft Azure, Nutanix AHV, or Oracle Linux VM/Red Hat Virtualization, such a deployment is&nbsp;<b>not impacted</b>&nbsp;by the vulnerability discussed in this article.</p>
                   <p>You can verify if Veeam Backup &amp; Replication manages any of these affected backup appliances by checking the&nbsp;<b>Backup Infrastructure &gt; Managed Servers</b>&nbsp;list for any of the following entry types:</p>
                   <ul>
                    <li>Nutanix AHV / Nutanix Prism Central / Nutanix AHV Cluster</li>
                    <li>AWS backup appliance</li>
                    <li>Microsoft Azure backup appliance</li>
                    <li>Google Cloud backup appliance</li>
                    <li>oVirt KVM Manager</li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Veeam Backup for Microsoft Azure Vulnerability - CVE-2025-23082]]></title>
 <link href="https://www.veeam.com/kb4709"/> 
 <id>https://www.veeam.com/kb4709</id>
 <updated>2025-01-13T00:00:00Z</updated>
 <published>2025-01-13T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup for Microsoft Azure]]></name>
 </author>
 <summary><![CDATA[Veeam Backup for Microsoft Azure Vulnerability - CVE-2025-23082]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Veeam Backup <i>for Microsoft Azure</i> Vulnerability<br>
          (CVE-2025-23082)</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4709</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup <i>for Microsoft Azure</i> | 7</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2025-01-13</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-01-29</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-f221e257a4" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__title">
               Article Applicability
              </div>
              <div class="notice__text veeam-text">
               <p>This article documents a vulnerability discovered in the <b>Veeam Backup <i>for Microsoft Azure</i>&nbsp;</b>backup appliance, which is used by Veeam Backup &amp; Replication&nbsp;to protect Microsoft Azure workloads.<br></p>
               <p>If a Veeam Backup &amp; Replication deployment is not protecting Microsoft Azure workloads, such a deployment is not impacted by the vulnerability discussed in this article.</p>
               <p>You can verify if Veeam Backup &amp; Replication manages a Veeam Backup for Microsoft Azure backup appliance by checking the <b>Backup Infrastructure &gt; Managed Servers</b> list for any '<i>Microsoft Azure backup appliance'</i> type entries.</p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>CVE-2025-23082</b></h4>
                   <p>A vulnerability that may allow an attacker to utilize Server-Side Request Forgery (SSRF) to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.</p>
                   <p>Affects <b>Veeam Backup <i>for Microsoft Azure</i></b>&nbsp;7.1.0.22 and all&nbsp;<a href="https://www.veeam.com/kb4360" target="_blank" rel="noopener">earlier versions</a>.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.2<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N</span></span><br><b>Source:</b>&nbsp;Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   This vulnerability was fixed starting in the following build of Veeam Backup <i>for Microsoft Azure</i>:
                  </div>
                 </div>
                </div>
                <div class="resource-list-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="resource-list ">
                   <ul class="resource-list__container resource-list__container--column">
                    <li class="resource-list__item"><a class="resource-list__link" href="https://www.veeam.com/kb4662" target="_self"> <i class="resource-list__icon fa-solid fa-up-right-from-square"></i>Veeam Backup <i>for Microsoft Azure</i>&nbsp;7.1.0.59 </a></li>
                   </ul>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3]]></title>
 <link href="https://www.veeam.com/kb4693"/> 
 <id>https://www.veeam.com/kb4693</id>
 <updated>2024-12-03T00:00:00Z</updated>
 <published>2024-12-03T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[Vulnerabilities Resolved in Veeam Backup & Replication 12.3]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title center 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Vulnerabilities Resolved in Veeam Backup &amp; Replication 12.3</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4693</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 12 | 12.1 | 12.2<br>
                  Veeam Agent&nbsp;<i>for Microsoft Windows</i> | 6.0 | 6.1 | 6.2</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2024-12-03</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-03-14</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__text veeam-text">
               <p>All vulnerabilities documented in this article were resolved in <a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3</a>.<br></p>
               <p><a href="https://www.veeam.com/products/downloads/latest-version.html" target="_blank" rel="noopener">Veeam Product Latest Version Download Page</a></p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-0740a78c18" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Veeam Backup &amp; Replication</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h3><b>Issue Details</b></h3>
                   <p>All vulnerabilities disclosed in this section affect&nbsp;<b>Veeam Backup &amp; Replication 12.2.0.334</b>&nbsp;and all&nbsp;<a href="https://www.veeam.com/kb2680" target="_blank" rel="noopener">earlier version 12 builds</a>.<br><i><sub><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.</sub></i></p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-40717</b></h5>
                   <p>A vulnerability allows an authenticated user with a role assigned in the <a href="https://helpcenter.veeam.com/docs/backup/vsphere/configuring_users.html" target="_blank" rel="noopener">Users and Roles settings</a> on the backup server to execute a script with elevated privileges by configuring it as a <a href="https://helpcenter.veeam.com/docs/backup/vsphere/backup_job_advanced_scripts_vm.html" target="_blank" rel="noopener">pre-job or post-job task</a>, thereby causing the script to be executed as LocalSystem.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source: </b>Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-42451</b></h5>
                   <p>A vulnerability allows an authenticated user with a role assigned in the Users and Roles settings on the backup server to access all saved credentials in a human-readable format.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b> <span class="veeam-tooltip">7.7<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</span></span><br><b>Source:&nbsp;</b>Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-42452</b></h5>
                   <p>A vulnerability allows an authenticated user with a role assigned in the Users and Roles settings on the backup server to remotely upload files to connected ESXi hosts with elevated privileges.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source:</b>&nbsp;Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-42453</b></h5>
                   <p>A vulnerability allows an authenticated user with a role assigned in the Users and Roles settings on the backup server to control and modify the configuration of connected virtual infrastructure hosts.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source:</b>&nbsp;Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-42455</b></h5>
                   <p>A vulnerability that allows an authenticated user with a role assigned in the Users and Roles settings on the backup server to connect to remote services and exploit insecure deserialization by sending a serialized temporary file collection, thereby enabling the deletion of any file on the system with service account privileges.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.1<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</span></span><br><b>Source:</b> Reported by&nbsp;Sina Kheirkhah of <a href="https://watchtowr.com/" target="_blank" rel="noopener">watchTowr</a>.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-42456</b></h5>
                   <p>A vulnerability that allows an authenticated user with a role assigned in the Users and Roles settings on the backup server to gain access to privileged methods and control critical services.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">8.8<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source:</b>&nbsp;Reported via HackerOne.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-42457</b></h5>
                   <p>A vulnerability that allows an authenticated user with certain assigned operator roles in the Users and Roles settings on the backup server to expose saved credentials by leveraging a combination of methods in the remote management interface.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.7<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</span></span><br><b>Source:</b>&nbsp;Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-45204</b></h5>
                   <p>A vulnerability that allows an authenticated user with an assigned role in the Users and Roles settings on the backup server to exploit insufficient permissions in credential handling, potentially leading to the leakage of NTLM hashes of saved credentials.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.7<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N</span></span><br><b>Source:</b>&nbsp;Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h3><b>Solution</b></h3>
                   <p>The vulnerabilities documented in this section were fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Backup &amp; Replication 12.3 (build 12.3.0.310)</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <h3><b>Mitigation Information</b></h3>
                  <p><br>
                    The Veeam Backup &amp; Replication vulnerabilities discussed in this section are related to the ability of an authenticated malicious user with a limited <a href="https://helpcenter.veeam.com/docs/backup/vsphere/configuring_users.html" target="_blank" rel="noopener">role</a>&nbsp;(Viewer/Operator) to perform certain actions that are normally only possible with administrative privileges on the backup server.&nbsp; <b>To mitigate these vulnerabilities until the backup server can be upgraded to version 12.3, simply remove untrusted and/or unnecessary users from the <a href="https://helpcenter.veeam.com/docs/backup/vsphere/configuring_users.html" target="_blank" rel="noopener">Users and Roles settings</a> on the backup server for the time being.</b></p>
                  <ul>
                   <li>Review all users assigned a&nbsp;<a href="https://helpcenter.veeam.com/docs/backup/vsphere/configuring_users.html" target="_blank" rel="noopener">Role</a>&nbsp;within Veeam Backup &amp; Replication.</li>
                   <li>For each user with an Operator or View role,&nbsp;assess internal necessity and remove access for users who do not strictly need it.</li>
                  </ul>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Veeam Agent&nbsp;<i>for Microsoft Windows</i></h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h3><b>Issue Details</b></h3>
                   <p>The vulnerability disclosed in this section affects&nbsp;<b>Veeam Agent&nbsp;<i>for Microsoft Windows</i>&nbsp;6.2 </b>and all&nbsp;<a href="https://www.veeam.com/kb2683" target="_blank" rel="noopener">earlier version 6 builds</a>.<br><i><sub><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.</sub></i></p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h5><b>CVE-2024-45207</b></h5>
                   <p>A vulnerability could lead to a DLL injection attack when the PATH environment variable is altered to include directories where an attacker can write files.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.0<span class="veeam-tooltip-text">CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</span></span><br><b>Source:&nbsp;</b>Reported via HackerOne by Faisal Alghamdi of Saudi Aramco.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h3><b>Solution</b></h3>
                   <p>The vulnerability documented in this section was fixed starting in the following build:</p>
                   <ul>
                    <li><a href="https://www.veeam.com/kb4696" target="_blank" rel="noopener">Veeam Agent&nbsp;<i>for Microsoft Windows</i> 6.3 <i>(build&nbsp;6.3.0.177)</i> — Included with Veeam Backup &amp; Replication 12.3</a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <h3><b>Mitigation Information</b></h3>
                  <p>The Veeam Agent&nbsp;<i>for Microsoft Windows</i> vulnerability discussed in this section can <b>only </b>be exploited in environments where directories that can be written to by untrusted users have been added to the PATH environment variable and whose presence is classified as a known <a href="" target="_self">CWE-426</a> weakness. As such, this vulnerability can be mitigated by removing such directories from the PATH variable.<br><b> Note:</b> The default Windows PATH environment variable does not include paths writable by untrusted users.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Veeam Service Provider Console Vulnerability (CVE-2024-42448 | CVE-2024-42449)]]></title>
 <link href="https://www.veeam.com/kb4679"/> 
 <id>https://www.veeam.com/kb4679</id>
 <updated>2024-12-03T00:00:00Z</updated>
 <published>2024-12-03T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Service Provider Console]]></name>
 </author>
 <summary><![CDATA[Veeam Service Provider Console Vulnerability (CVE-2024-42448 | CVE-2024-42449)]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Veeam Service Provider Console Vulnerabilities<br>
          (CVE-2024-42448 | CVE-2024-42449)</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4679</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Service Provider Console | 8.1</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2024-12-03</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2024-12-04</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-080b1b3dd1" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__title">
               Article Applicability
              </div>
              <div class="notice__text veeam-text">
               <p>This article documents a vulnerability discovered in Veeam Service Provider Console.</p>
               <p>This vulnerability does <b><span class="text-color-error">not</span></b> affect other Veeam products (e.g., Veeam Backup &amp; Replication, Veeam Agent&nbsp;<i>for Microsoft Windows</i>, Veeam ONE).</p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>All vulnerabilities disclosed in this section affect Veeam Service Provider Console 8.1.0.21377&nbsp;and all&nbsp;<a href="https://www.veeam.com/kb4464" target="_blank" rel="noopener">earlier versions 8 and 7 builds</a>.</p>
                   <p><sup><b>Note:</b>&nbsp;Private fixes for the Veeam Service Provider Console increase the build number. Therefore, if a private fix has been applied, the deployed build number may exceed the GA build number mentioned above. In such instances, any deployed build number lower than the build reference in the <a href="#solution" target="_self">Solution</a> section should be considered affected.</sup><br><i><sub><a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">Unsupported product versions</a>&nbsp;are not tested, but are likely affected and should be considered vulnerable.</sub></i></p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2024-42448</b></h4>
                   <p>From the VSPC management agent machine, under the condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">9.9<span class="veeam-tooltip-text">CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2024-42449</b></h4>
                   <p>From the VSPC management agent machine, under the condition that the management agent is authorized on the server, it is possible to leak an NTLM hash of the VSPC server service account and delete files on the VSPC server machine.</p>
                   <p><b>Severity:</b>&nbsp;High<br><b>CVSS v3.1 Score:</b>&nbsp;<span class="veeam-tooltip">7.1<span class="veeam-tooltip-text">CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</span></span><br><b>Source: </b>Discovered during internal testing.</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                 <span class="anchor" id="solution"></span>
                </div>
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   The vulnerability documented in this article was fixed starting in the following build of Veeam Service Provider Console:
                  </div>
                 </div>
                </div>
                <div class="resource-list-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="resource-list ">
                   <ul class="resource-list__container resource-list__container--column">
                    <li class="resource-list__item"><a class="resource-list__link" href="https://www.veeam.com/kb4651" target="_self"> <i class="resource-list__icon fa-solid fa-up-right-from-square"></i>Veeam Service Provider Console&nbsp;8.1.0.21999 </a></li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                  <div class="notice notice--danger">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__title">
                     Critical Update
                    </div>
                    <div class="notice__text veeam-text">
                     We encourage service providers using <a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">supported</a> versions of Veeam Service Provider Console (versions 7 &amp; 8) to update to the latest cumulative patch. Service Providers using unsupported versions are strongly encouraged to upgrade to the <a href="https://www.veeam.com/availability-console-download.html" target="_blank" rel="noopener">latest version of Veeam Service Provider Console</a>.
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                  <div class="notice notice--warning">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__title">
                     No Mitigations Available
                    </div>
                    <div class="notice__text veeam-text">
                     No mitigation method is available for these vulnerabilities. The only remedy is to upgrade to <a href="https://www.veeam.com/kb4464" target="_blank" rel="noopener">the latest version of Veeam Service Provider Console</a>.
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)]]></title>
 <link href="https://www.veeam.com/kb4682"/> 
 <id>https://www.veeam.com/kb4682</id>
 <updated>2024-11-06T00:00:00Z</updated>
 <published>2024-11-06T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Veeam Backup Enterprise Manager Vulnerability<br>
          (CVE-2024-40715)</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4682</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 10 | 11 | 12 | 12.1 | 12.2</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2024-11-06</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2024-11-12</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="experience-fragment experiencefragment aem-GridColumn aem-GridColumn--default--12">
           <div id="experience-fragment-070c0d80ff" class="cmp-experiencefragment cmp-experiencefragment--_vulnstatement">
            <div class="xf-content-height">
             <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
              <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
               <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                <div class="notice notice--success">
                 <div class="notice__icon">
                  <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                 </div>
                 <div class="notice__content">
                  <div class="notice__title">
                   Veeam Software Security Commitment
                  </div>
                  <div class="notice__text veeam-text">
                   <span class="veeam-text__caption">Veeam®&nbsp;is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a&nbsp;<a href="https://www.veeam.com/vulnerability-disclosure.html" target="_blank" rel="noopener">Vulnerability Disclosure Program (VDP)</a>&nbsp;for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay.</span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--warning">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__title">
               Article Applicability
              </div>
              <div class="notice__text veeam-text">
               <p>This article documents a vulnerability discovered in <a href="https://helpcenter.veeam.com/docs/backup/em/introduction.html" target="_blank" rel="noopener"><b>Veeam Backup Enterprise Manager (VBEM)</b></a>, a supplementary application customers may deploy to manage Veeam Backup &amp; Replication (VBR) using a web console.</p>
               <p>Deploying <b>VBEM</b> is optional; not all environments will have it installed. As such, if<b> VBEM</b> was not deployed in your environment, that environment would <b>not</b> be impacted by this vulnerability.<br><br></p>
               <hr>
               <p><b>Tip:</b> You can identify if VBEM is installed by checking for the <b>Veeam Backup Enterprise Manager</b> service&nbsp;or by running the following PowerShell command <u>on the <a href="https://helpcenter.veeam.com/docs/backup/vsphere/backup_server.html" target="_blank" rel="noopener">Veeam Backup Server</a></u> to see if VBR reports that it is managed by a VBEM deployment.</p>
               <pre>Get-VBRServer | Out-Null
[Veeam.Backup.Core.SBackupOptions]::GetEnterpriseServerInfo() | Format-List
</pre>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <h4><b>CVE-2024-40715</b></h4>
                   <p>This vulnerability in Veeam Backup Enterprise Manager allows attackers to bypass the authentication while performing a Man-in-the-Middle (MITM) attack.</p>
                   <p><b>Severity:</b> High<br><b>CVSS v3.1 Score:</b> <span class="veeam-tooltip">7.7<span class="veeam-tooltip-text">AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L</span></span></p>
                   <p><i><sup>This vulnerability was reported by ZDI through Hacker One.</sup></i></p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>The vulnerability documented in this article was resolved with a hotfix for Veeam Backup Enterprise Manager 12.2.0.334. This hotfix is available directly via this article and was integrated into repackaged ISOs for Veeam Backup &amp; Replication and Veeam Data Platform released on 2024-11-06.</p>
                  <ul>
                   <li>For environments where Veeam Backup Enterprise Manager 12.2.0.334 is already installed, download the hotfix from the Download Information section below.</li>
                   <li>For environments where Veeam Backup Enterprise Manager&nbsp;12.1.2.172 or older is installed, please upgrade to 12.2.0.334 using the <a href="https://www.veeam.com/send_license/vmware-esx-backup/" target="_blank" rel="noopener">latest Veeam Backup &amp; Replication ISO</a>. 
                    <div data-selector-id="text" class="sc-eCImPb gubfha vm-Text undefined" style="width: 200.0px;">
                     &nbsp;
                    </div></li>
                  </ul>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Download Information</h2>
                  </div>
                 </div>
                </div>
                <div class="universal-button-component aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="universal-button   " data-component="UniversalButtonComponent" data-config="{
        &quot;ctaLink&quot;: &quot;https://www.veeam.com/download_add_packs/vmware-esx-backup/kb4682&quot;,
        &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
        &quot;eventCategory&quot;: &quot;&quot;,
        &quot;eventAction&quot;: &quot;&quot;,
        &quot;eventLabel&quot;: &quot;Download button - en&quot;,
        &quot;openPopup&quot;: false,
        &quot;sticky&quot;: false
     }">
                   <div class="universal-button__container">
                    <a href="https://www.veeam.com/download_add_packs/vmware-esx-backup/kb4682" aria-label="Download button - en" class="universal-button__button universal-button__button--primary universal-button__button--text-center "> <span class="universal-button__label">Download Hotfix</span></a>
                    <div class="universal-button__description">
                     <p></p>
                     <p style="text-align: left;"><sup>Filename:&nbsp;veeam_backup_12.2.0.334_PrivateFix_TF812030.zip</sup></p>
                     <p style="text-align: left;"><b>MD5:&nbsp;</b><code>AEE65885214721E5757B8B05397590FB</code><br><b>SHA1:&nbsp;</b><code>7EFD3B89185CCB4230628A0CCA4ACE3D5BE5CD51</code></p>
                     <p></p>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Deployment Information</h2>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                  <div class="notice notice--warning">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__title">
                     Version Requirement
                    </div>
                    <div class="notice__text veeam-text">
                     <p>The hotfix requires&nbsp;the existing Veeam Backup Enterprise Manager deployment to be running <b>12.2.0.334</b>. You can check which version of Veeam Backup Enterprise Manager is installed by viewing the <b>About</b>&nbsp;section of the&nbsp;<b>Configuration</b>&nbsp;view.</p>
                     <p>If an earlier version of Veeam Backup Enterprise Manager (12.1.2.172 or older) is deployed, upgrade to&nbsp;12.2.0.334 using the <a href="https://www.veeam.com/send_license/vmware-esx-backup/" target="_blank" rel="noopener">latest Veeam Backup &amp; Replication ISO</a>, which contains the hotfix and will automatically deploy it.</p>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <ol>
                    <li>If Veeam Backup Enterprise Manager is installed on the same machine as Veeam Backup &amp; Replication:<br>
                      On the Veeam Backup Server, close all open Veeam Backup &amp; Replication Consoles, and ensure no processes named<i> veeam.backup.shell.exe</i> are running.</li>
                    <li>Unzip the hotfix and run the hotfix installer on the machine where Veeam Backup Enterprise Manager is installed.<br>
                      (veeam_backup_12.2.0.334_PrivateFix_TF812030.exe)</li>
                   </ol>
                   <p><br><b>Note: </b>If running the hotfix results in the error "<b>This update is not compatible with installed software version.</b>" it means that either:</p>
                   <ul>
                    <li>Veeam Backup Enterprise Manager is not installed on the machine where the hotfix was run.<br><br>
                      or</li>
                    <li>The version of Veeam Backup Enterprise Manager installed on the machine where the hotfix was run is not 12.2.0.334.</li>
                   </ul>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--md" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__title">
                     Reboot May Be Required
                    </div>
                    <div class="notice__text veeam-text">
                     <p>Please note that a reboot <i>may</i>&nbsp;be required after installing the hotfix.&nbsp;</p>
                     <p>Please plan accordingly.</p>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Deployment Validation</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   As this is a hotfix, the build number of the software will not be changed. Therefore, validating that the hotfix has been deployed requires checking the hash value of the file present on the system and comparing it to the known hash value of the file included in the hotfix.
                  </div>
                 </div>
                </div>
                <div class="veeam-table-component aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="veeam-table-container  veeam-component__component-spacing-below--lg">
                  <div class="veeam-table" data-component="VeeamTableComponent" data-config="{
                &quot;isAuthor&quot;: false
             }">
                   <div class="veeam-table-wrapper">
                    <table cellpadding="1" cellspacing="0" border="1">
                     <tbody>
                      <tr>
                       <td class="veeam-table__cell--title">Hotfix Filename</td>
                       <td class="veeam-table__cell--title">SHA1 Hash</td>
                      </tr>
                      <tr>
                       <td>Veeam.Backup.Enterprise.Core.dll</td>
                       <td><code>FDC176FCE4825023F14462A51541C1DF591B28AC</code></td>
                      </tr>
                     </tbody>
                    </table>
                   </div>
                   <div class="veeam-table__mobile-controls-container">
                    <div class="veeam-table__mobile-controls">
                     <div class="veeam-table__mobile-control-container">
                      <button class="veeam-table__mobile-control veeam-table__mobile-control--prev"><i class="v-icon fa-sharp fa-solid fa-chevron-left"></i></button>
                     </div> Swipe to show more of the table 
                     <div class="veeam-table__mobile-control-container">
                      <button class="veeam-table__mobile-control veeam-table__mobile-control--next"><i class="v-icon fa-sharp fa-solid fa-chevron-right"></i></button>
                     </div>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Check The DLL's Hash</b></h4>
                   <p>Use the following PowerShell command to check the SHA1 hash value of the DLL.</p>
                  </div>
                 </div>
                </div>
                <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="code-block  veeam-component__component-spacing-below--md" data-component="CodeBlockComponent">
                  <div class="code-toolbar">
                   <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token function">Get-FileHash</span> <span class="token operator">-</span>Path <span class="token string">'C:\Program Files\Veeam\Backup and Replication\Enterprise Manager\Veeam.Backup.Enterprise.Core.dll'</span> <span class="token operator">-</span>Algorithm SHA1<span class="line-numbers-rows"><span></span></span></code></pre>
                   <div class="toolbar">
                    <div class="toolbar-item">
                     <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[CVE-2023-38547 | CVE-2023-38548 | CVE-2023-38549 | CVE-2023-41723]]></title>
 <link href="https://www.veeam.com/kb4508"/> 
 <id>https://www.veeam.com/kb4508</id>
 <updated>2023-11-06T00:00:00Z</updated>
 <published>2023-11-06T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam ONE]]></name>
 </author>
 <summary><![CDATA[Security update regarding: CVE-2023-38547 | CVE-2023-38548 | CVE-2023-38549 | CVE-2023-41723]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">
         <p>CVE-2023-38547 | CVE-2023-38548&nbsp;</p>
         <p>CVE-2023-38549 | CVE-2023-41723</p></h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4508</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam ONE | 11 | 12<br>
                  Veeam Recovery Orchestrator | 6.0<br>
                  Veeam Disaster Recovery Orchestrator | 5.0<br>
                  Veeam Availability Orchestrator | 4.0</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2023-11-06</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2024-01-10</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="side-menu-container-component parbase aem-GridColumn aem-GridColumn--default--12">
      <div class="side-navigation-container  ">
       <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
        <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
         <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
          <div class="bg-image-size-contain bg-image-position-left   ">
           <div class="  " style="max-width: 100%;">
            <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
             <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
              <div class=" veeam-component__component-spacing-below--sm">
               <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
                <div class="bg-image-size-contain bg-image-position-left      ">
                 <div class="  " style="max-width: 100%;">
                  <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                   <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                     <div class="notice notice--success">
                      <div class="notice__icon">
                       <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                      </div>
                      <div class="notice__content">
                       <div class="notice__text veeam-text">
                        <p>Veeam ONE 12<b>.1</b>&nbsp;is not affected by the vulnerabilities discussed on this page.&nbsp;</p>
                        <p>Additionally, Veeam Recovery Orchestrator 7 is not affected by these vulnerabilities as it uses Veeam ONE 12<b style="">.1</b>.</p>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                    <span class="anchor" id="details"></span>
                   </div>
                   <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                     <div class="section-title__title-block">
                      <h2 class="section-title__title">Issue Details</h2>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                    <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                     <h4><b>CVE-2023-38547</b></h4>
                     <p>A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.</p>
                     <p><b>Affected Version(s)*:&nbsp;</b>Veeam ONE 11, 11a, 12<br><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3.1:</b>&nbsp;9.9</p>
                     <p>&nbsp;</p>
                     <h4><b>CVE-2023-38548</b></h4>
                     <p>A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.</p>
                     <p><b>Affected Version(s)*: </b>Veeam ONE 12<b><br>
                        Severity:</b> Critical<br><b>CVSS v3.1 score:&nbsp;</b> 9.8</p>
                     <p>&nbsp;</p>
                     <h4><b>CVE-2023-38549</b></h4>
                     <p>A vulnerability in Veeam ONE allows a user with the&nbsp;<a href="https://helpcenter.veeam.com/docs/one/deployment/security_groups.html?zoom_highlight=Power%20Users" target="_blank" rel="noopener">Veeam ONE Power User</a>&nbsp;role to&nbsp;obtain the access token of a user with the&nbsp;<a href="https://helpcenter.veeam.com/docs/one/deployment/security_groups.html?zoom_highlight=Veeam%20ONE%20Administrators" target="_blank" rel="noopener">Veeam ONE Administrator</a>&nbsp;role through the use of XSS.<br><b>Note:</b> The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.</p>
                     <p><b>Affected Version(s)*:</b> Veeam ONE 11, 11a, 12<br><b>Severity:</b> Medium<br><b>CVSS v3.1 score:</b>&nbsp;4.5</p>
                     <p>&nbsp;</p>
                     <h4><b>CVE-2023-41723</b></h4>
                     <p>A vulnerability in Veeam ONE allows a user with the&nbsp;<a href="https://helpcenter.veeam.com/docs/one/reporter/permissions_vs_security_groups.html?zoom_highlight=Veeam%20ONE%20Read-Only%20Users" target="_blank" rel="noopener">Veeam ONE Read-Only User</a> role to view the <a href="https://helpcenter.veeam.com/docs/one/reporter/manage_dashboard_schedules.html" target="_blank" rel="noopener">Dashboard Schedule</a>.<br><b>Note:</b> The criticality of this vulnerability is reduced because the user with the Read-Only role is only able to view the schedule and cannot make changes.</p>
                     <p><b>Affected Version(s)*:</b>&nbsp;Veeam ONE 11, 11a, 12<br><b>Severity:</b>&nbsp;Medium<br><b>CVSS v3.1 score:</b>&nbsp;4.3</p>
                     <p>&nbsp;</p>
                     <p>*Vulnerability testing was only performed using <a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener">actively supported</a> versions of Veeam ONE.</p>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
             <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
              <div class=" veeam-component__component-spacing-below--sm">
               <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
                <div class="bg-image-size-contain bg-image-position-left      ">
                 <div class="  " style="max-width: 100%;">
                  <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                   <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                    <span class="anchor" id="solution"></span>
                   </div>
                   <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="section-title left 
            section-title--only-title  ">
                     <div class="section-title__title-block">
                      <h2 class="section-title__title">Solution</h2>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                      <p>A hotfix to resolve these vulnerabilities is available for the following versions:</p>
                      <ul>
                       <li>Veeam ONE 12&nbsp;P20230314 <i>(12.0.1.2591)</i></li>
                       <li>Veeam ONE 11a <i>(11.0.1.1880)</i></li>
                       <li>Veeam ONE 11 <i>(11.0.0.1379)</i></li>
                      </ul>
                     </div>
                    </div>
                   </div>
                   <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                     <div class="notice notice--success">
                      <div class="notice__icon">
                       <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                      </div>
                      <div class="notice__content">
                       <div class="notice__title">
                        Veeam ONE is a Component of Veeam Recovery Orchestrator
                       </div>
                       <div class="notice__text veeam-text">
                        <p>Veeam Recovery Orchestrator&nbsp;<i>(formerly known as Veeam Disaster Recovery Orchestrator or Veeam Availability Orchestrator)</i> utilizes an embedded deployment of Veeam ONE.</p>
                        <p>Customers using the following versions of Orchestrator should install the embedded Veeam ONE build's hotfix from this article.</p>
                        <ul>
                         <li>Veeam Recovery Orchestrator 6&nbsp;P20230419 uses Veeam ONE 12 P20230314 <i>(build 12.0.1.2591)<br></i><br><b> Note:</b>&nbsp;Veeam Recovery Orchestrator 6 GA shipped with Veeam ONE 12.0.0.2498, which is not compatible with this hotfix. Check which version of Veeam ONE is installed; if 12.0.0.2498 is installed, <a href="https://www.veeam.com/kb4437#manualupdate" target="_blank" rel="noopener">update Veeam Recovery Orchestrator as documented in KB4437</a>.</li>
                         <li>Veeam Disaster Recovery Orchestrator 5 uses Veeam ONE 11a <i>(build 11.0.1.1880)</i></li>
                         <li>Veeam Availability Orchestrator 4 uses Veeam ONE 11 <i>(build 11.0.0.1379)</i></li>
                        </ul>
                        <p>&nbsp;</p>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
             <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
              <div class=" veeam-component__component-spacing-below--sm">
               <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
                <div class="bg-image-size-contain bg-image-position-left      ">
                 <div class="  " style="max-width: 100%;">
                  <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                   <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                    <span class="anchor" id="downloadinfo"></span>
                   </div>
                   <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                     <div class="section-title__title-block">
                      <h2 class="section-title__title">Download Information</h2>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class=" veeam-component__component-spacing-below--ss">
                     <div class="veeam-text  " data-component="VeeamTextComponent">
                      <h4><b>Check Veeam ONE Build Number</b></h4>
                      <p>Before downloading the hotfix, check which version of Veeam ONE is installed using one of the methods below:</p>
                      <ul>
                       <li>Check under Help &gt; About in the Veeam ONE Client.</li>
                       <li>Check within Apps and Features or Programs and Features (Appwiz.cpl).</li>
                       <li>Run the following command on the Veeam ONE server:</li>
                      </ul>
                     </div>
                    </div>
                   </div>
                   <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="code-block  veeam-component__component-spacing-below--lg" data-component="CodeBlockComponent">
                     <div class="code-toolbar">
                      <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token function">Get-Package</span> <span class="token operator">-</span>name <span class="token string">"Veeam ONE*"</span><span class="line-numbers-rows"><span></span></span></code></pre>
                      <div class="toolbar">
                       <div class="toolbar-item">
                        <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                     <div class="notice notice--danger">
                      <div class="notice__icon">
                       <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                      </div>
                      <div class="notice__content">
                       <div class="notice__title">
                        Hotfix Must Match Installed Build
                       </div>
                       <div class="notice__text veeam-text">
                        <p>The hotfixes below were built for the specific Veeam ONE build numbers listed.</p>
                        <p>If a hotfix package intended for a specific build number is deployed on a Veeam ONE server that does not have that matching build installed,<b> <span class="text-color-error">the Veeam ONE Reporting Service will fail to start</span></b>.</p>
                        <p>Please review the steps in the deployment section and heed the advice to double-check which Veeam ONE build is installed before applying the hotfix.</p>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class=" veeam-component__component-spacing-below--sm">
                     <div class="veeam-text  " data-component="VeeamTextComponent">
                      <h4><b>Download Hotfix That Matches Installed Build Number</b></h4>
                     </div>
                    </div>
                   </div>
                   <div class="universal-button-component aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="universal-button   " data-component="UniversalButtonComponent" data-config="{
        &quot;ctaLink&quot;: &quot;https://www.veeam.com/download_add_packs/virtualization-management-one-solution/hfkb4508_12.0.1.2591/&quot;,
        &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
        &quot;eventCategory&quot;: &quot;&quot;,
        &quot;eventAction&quot;: &quot;&quot;,
        &quot;eventLabel&quot;: &quot;Download button - en&quot;,
        &quot;openPopup&quot;: false,
        &quot;sticky&quot;: false
     }">
                      <div class="universal-button__container">
                       <a href="https://www.veeam.com/download_add_packs/virtualization-management-one-solution/hfkb4508_12.0.1.2591/" aria-label="Download button - en" class="universal-button__button universal-button__button--primary universal-button__button--text-center "> <span class="universal-button__label">Hotfix for 12.0.1.2591</span></a>
                       <div class="universal-button__description">
                        <p></p>
                        <div style="text-align: left;">
                         For Veeam ONE 12&nbsp;P20230314 <i>(build 12.0.1.2591)</i>
                         <br>
                         <br>
                        </div>
                        <div style="text-align: left;">
                         <b>MD5:</b> <code>4BA7E812769F0C4FB98331E20B498C01</code>
                         <br><b>SHA1:</b> <code>1604B837E25041D863B432A6C3D1EE12E640ED62</code>
                        </div>
                        <div style="text-align: left;">
                         &nbsp;
                        </div>
                        <div style="text-align: left;">
                         <b><span class="text-color-error">Attention:</span></b> This hotfix is&nbsp;<span class="text-color-error"><b><u>not</u></b>&nbsp;</span>compatible with Veeam ONE 12 GA (build 12.0.0.<b>2498</b>). If Veeam ONE 12.0.0.2498 is installed, it <u>must</u> be&nbsp;<a href="https://www.veeam.com/kb4430#manualupdate" target="_blank" rel="noopener">updated</a>&nbsp;to <a href="https://www.veeam.com/kb4430" target="_blank" rel="noopener">12.0.1.2591</a> before applying the hotfix. Applying the hotfix to 12.0.0.2498 will cause the Veeam ONE Reporting Service to fail to start.
                        </div>
                        <p></p>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="universal-button-component aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="universal-button   " data-component="UniversalButtonComponent" data-config="{
        &quot;ctaLink&quot;: &quot;https://www.veeam.com/download_add_packs/virtualization-management-one-solution/hfkb4508_11.0.1.1880/&quot;,
        &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
        &quot;eventCategory&quot;: &quot;&quot;,
        &quot;eventAction&quot;: &quot;&quot;,
        &quot;eventLabel&quot;: &quot;Download button - en&quot;,
        &quot;openPopup&quot;: false,
        &quot;sticky&quot;: false
     }">
                      <div class="universal-button__container">
                       <a href="https://www.veeam.com/download_add_packs/virtualization-management-one-solution/hfkb4508_11.0.1.1880/" aria-label="Download button - en" class="universal-button__button universal-button__button--primary universal-button__button--text-center "> <span class="universal-button__label">Hotfix for 11.0.1.1880</span></a>
                       <div class="universal-button__description">
                        <p></p>
                        <div style="text-align: left;">
                         For Veeam ONE 11a<i> (build 11.0.1.1880)</i>
                        </div>
                        <div style="text-align: left;">
                         &nbsp;
                        </div>
                        <div style="text-align: left;">
                         <b>MD5:</b> <code>0DCDD67FE151FFC8242469B75AED3025</code>
                         <br><b>SHA1:</b> <code>1AFB3B762BF46B76337A94D30066EA7F3AABBCB1</code>
                        </div>
                        <p></p>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="universal-button-component aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--md">
                     <div class="universal-button   " data-component="UniversalButtonComponent" data-config="{
        &quot;ctaLink&quot;: &quot;https://www.veeam.com/download_add_packs/virtualization-management-one-solution/hfkb4508_11.0.0.1379/&quot;,
        &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
        &quot;eventCategory&quot;: &quot;&quot;,
        &quot;eventAction&quot;: &quot;&quot;,
        &quot;eventLabel&quot;: &quot;Download button - en&quot;,
        &quot;openPopup&quot;: false,
        &quot;sticky&quot;: false
     }">
                      <div class="universal-button__container">
                       <a href="https://www.veeam.com/download_add_packs/virtualization-management-one-solution/hfkb4508_11.0.0.1379/" aria-label="Download button - en" class="universal-button__button universal-button__button--primary universal-button__button--text-center "> <span class="universal-button__label">Hotfix for 11.0.0.1379</span></a>
                       <div class="universal-button__description">
                        <p></p>
                        <div style="text-align: left;">
                         For Veeam ONE 11<i> (build 11.0.0.1379)</i>
                        </div>
                        <div style="text-align: left;">
                         &nbsp;
                        </div>
                        <div style="text-align: left;">
                         <b>MD5:</b> <code>93B87925C4AFB030DDA6388DF31E5984</code>
                         <br><b>SHA1:</b> <code>74AD4B5A18A16276F74043F3098D6ED6132C97D0</code>
                        </div>
                        <p></p>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
             <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
              <div class=" veeam-component__component-spacing-below--sm">
               <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
                <div class="bg-image-size-contain bg-image-position-left      ">
                 <div class="  " style="max-width: 100%;">
                  <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                   <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                    <span class="anchor" id="deployinfo"></span>
                   </div>
                   <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                     <div class="section-title__title-block">
                      <h2 class="section-title__title">Deployment Information</h2>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--ss">
                     <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                      <ol>
                       <li><b>Verify </b>the version of Veeam ONE installed using one of the methods below: 
                        <ul>
                         <li>Check under Help &gt; About in the Veeam ONE Client.</li>
                         <li>Check within Apps and Features or Progams and Features (Appwiz.cpl).</li>
                         <li>Run the following command on the Veeam ONE server:</li>
                        </ul></li>
                      </ol>
                     </div>
                    </div>
                   </div>
                   <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="code-block  veeam-component__component-spacing-below--ss" data-component="CodeBlockComponent">
                     <div class="code-toolbar">
                      <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token function">Get-Package</span> <span class="token operator">-</span>name <span class="token string">"Veeam ONE*"</span><span class="line-numbers-rows"><span></span></span></code></pre>
                      <div class="toolbar">
                       <div class="toolbar-item">
                        <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class=" veeam-component__component-spacing-below--md">
                     <div class="veeam-text  " data-component="VeeamTextComponent">
                      <b>Note:</b> If Veeam ONE&nbsp;12.0.0.<b>2498</b> is installed, it <u>must</u> be&nbsp;<a href="https://www.veeam.com/kb4430#manualupdate" target="_blank" rel="noopener">updated</a>&nbsp;to <a href="https://www.veeam.com/kb4430" target="_blank" rel="noopener">12.0.1.2591</a> before installing the hotfix.
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                      <ol start="2">
                       <li><b>Download</b>&nbsp;the hotfix package that matches the installed Veeam ONE build number.<br></li>
                       <li><b>Stop </b>the following services on the Veeam ONE server: 
                        <ul>
                         <li>Veeam ONE Monitoring Service</li>
                         <li>Veeam ONE Reporting Service</li>
                        </ul></li>
                       <li><b>Replace </b>the existing files with the files provided in the hotfix.<sup><b><br></b></sup><span class="veeam-text__caption"><b>Note:</b> The contents of the hotfix zip match the folder structure of the <span class="veeam-tooltip">Veeam ONE Reporter Server<span class="veeam-tooltip-text">Default location:<br>
                            C:\Program Files\Veeam\Veeam ONE\</span></span> folder. The hotfix files must be placed in the folders that match the folder within the hotfix zip.</span><br>
                        <ul>
                         <li>DLLs in the root of the hotfix zip go in: <i>C:\Program Files\Veeam\Veeam ONE\Veeam ONE Reporter Server\</i>
                          <ul>
                           <li>Veeam.Reporter.GrpcService.dll</li>
                           <li>Veeam.Reporter.WebApiService.dll<br></li>
                           <li>Veeam.Reporter.PackInstaller.dll</li>
                           <li>Veeam.Reporter.GrpcShared.dll<br><i><sup>This file is only in the hotfix for 12.0.1.2591, as it is related to the vulnerability that only affects Veeam ONE version 12.</sup></i></li>
                          </ul></li>
                         <li>Files in the Collecting folder within the hotfix go in: <i>C:\Program Files\Veeam\Veeam ONE\Veeam ONE Reporter</i> Server\<i>Collecting</i>\ 
                          <ul>
                           <li>Veeam.Retriever.exe<br></li>
                           <li>Veeam.Reporter.GrpcShared.dll<br><i><sup>This file is only in the hotfix for 12.0.1.2591, as it is related to the vulnerability that only affects Veeam ONE version 12.</sup></i></li>
                          </ul></li>
                         <li>Files in the Reporting folder within the hotfix go in: <i>C:\Program Files\Veeam\Veeam ONE\Veeam ONE Reporter</i> Server\Reporting\ 
                          <ul>
                           <li>Veeam.Reporter.Reporting.exe<br></li>
                           <li>Veeam.Reporter.GrpcShared.dll<br><i><sup>This file is only in the hotfix for 12.0.1.2591, as it is related to the vulnerability that only affects Veeam ONE version 12.</sup></i></li>
                          </ul></li>
                        </ul></li>
                       <li><b>Start </b>the services stopped in Step 3.</li>
                      </ol>
                      <p>&nbsp;</p>
                      <p>If you have any questions or require assistance, please&nbsp;<a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">create a&nbsp;Veeam Support case</a>.</p>
                     </div>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
             <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
              <div class=" veeam-component__component-spacing-below--sm">
               <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
                <div class="bg-image-size-contain bg-image-position-left      ">
                 <div class="  " style="max-width: 100%;">
                  <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                   <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                    <span class="anchor" id="validate"></span>
                   </div>
                   <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                     <div class="section-title__title-block">
                      <h2 class="section-title__title">Deployment Validation</h2>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--ss">
                     <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                      <p>As this is a hotfix, the build number of the software will not change. As such, validating the hotfix has been deployed requires checking the hash value of the files present and comparing them to the known hash values of the files included in the hotfix.</p>
                      <p><i>Click the version row to expand the list of files included with the hotfix and their known SHA1 hash values.</i></p>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-table-component aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="veeam-table-container  veeam-component__component-spacing-below--lg">
                     <div class="veeam-table" data-component="VeeamTableComponent" data-config="{
                &quot;isAuthor&quot;: false
             }">
                      <div class="veeam-table-wrapper">
                       <table cellpadding="1" cellspacing="0" border="1">
                        <tbody>
                         <tr>
                          <td class="veeam-table__cell--title">Filename</td>
                          <td class="veeam-table__cell--title">SHA1 Hash</td>
                         </tr>
                         <tr class="veeam-table__expandable-title-row">
                          <td class="veeam-table__cell--bg-pale-gray" colspan="2"><b>Veeam ONE&nbsp; 12.0.1.2591</b></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Collecting\Veeam.Reporter.GrpcShared.dll</td>
                          <td><code>AC5A2945728E8C60BCF4E879BCAC6B235F38B5B3</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Collecting\Veeam.Retriever.exe</td>
                          <td><code>8FCA25B1CD81D89E3B0A977B8AF5255487610969</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Reporting\Veeam.Reporter.GrpcShared.dll</td>
                          <td><code>827E1929916972E6ABA25DDA15F0CD5474EBBFB8</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Reporting\Veeam.Reporter.Reporting.exe</td>
                          <td><code>D1EC3C8E25C654106481F7DF9281BB271461E7AD</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.GrpcService.dll</td>
                          <td><code>269AFC1424BC58612AC97B08520473FEEF518D4A</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.GrpcShared.dll</td>
                          <td><code>F0ADE6C781D673B9DB84F14AD0C2D0BE847873BD</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.PackInstaller.dll</td>
                          <td><code>B02B20BB6E45E7E9DB2D68E8FDDAADF0ADA4BCF5</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.WebApiService.dll</td>
                          <td><code>4406F2F4F6D7F07811946D2637DD8BB8322E91E0</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-title-row">
                          <td class="veeam-table__cell--bg-pale-gray" colspan="2"><b>Veeam ONE 11.0.1.1880</b></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Collecting\Veeam.Retriever.exe</td>
                          <td><code>21D989ACF3AA191079D40FDAE06AE1B8AFBC9C8F</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Reporting\Veeam.Reporter.Reporting.exe</td>
                          <td><code>7359FE86A6160EF1C0C9CA913E7216DA622D6F32</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.GrpcService.dll</td>
                          <td><code>B6B4404D50817EB73927F211A570767D6A0D3DE0</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.PackInstaller.dll</td>
                          <td><code>CEB6EFCCB4CCA079501BE7A6DA225F2126761044</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.WebApiService.dll</td>
                          <td><code>28A7D7411EF41E939D1B8D6F669966EDB1C61B12</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-title-row">
                          <td class="veeam-table__cell--bg-pale-gray" colspan="2"><b>Veeam ONE 11.0.0.1379</b></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Collecting\Veeam.Retriever.exe</td>
                          <td><code>AE9EE91C786D097F65B8CB26CCA253E1B4724C2C</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>\Reporting\Veeam.Reporter.Reporting.exe</td>
                          <td><code>DDBE4199AA973CDD71A4F3A68B5B68CD109BFF1D</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.GrpcService.dll</td>
                          <td><code>990A1BAB5C408DC2CB53B2637E4FABCBDB943E96</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.PackInstaller.dll</td>
                          <td><code>717F85C39D2FAB41D720ABDDAB69B03C3AAD5ADD</code></td>
                         </tr>
                         <tr class="veeam-table__expandable-content-row">
                          <td>Veeam.Reporter.WebApiService.dll</td>
                          <td><code>1957C5C23C89348A9F0B9405CECC3C2985F858BB</code></td>
                         </tr>
                        </tbody>
                       </table>
                      </div>
                      <div class="veeam-table__mobile-controls-container">
                       <div class="veeam-table__mobile-controls">
                        <div class="veeam-table__mobile-control-container">
                         <button class="veeam-table__mobile-control veeam-table__mobile-control--prev"><i class="v-icon fa-sharp fa-solid fa-chevron-left"></i></button>
                        </div> Swipe to show more of the table 
                        <div class="veeam-table__mobile-control-container">
                         <button class="veeam-table__mobile-control veeam-table__mobile-control--next"><i class="v-icon fa-sharp fa-solid fa-chevron-right"></i></button>
                        </div>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="veeam-text  " data-component="VeeamTextComponent">
                      <h4><b>Check Existing File's Hash</b></h4>
                      <p>To check the hash value of an existing file, use the following PowerShell command with the correct path to the file being checked.</p>
                     </div>
                    </div>
                   </div>
                   <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class="code-block  veeam-component__component-spacing-below--md" data-component="CodeBlockComponent">
                     <div class="code-toolbar">
                      <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token function">Get-FileHash</span> <span class="token operator">-</span>Path &lt;file-path&gt; <span class="token operator">-</span>Algorithm SHA1<span class="line-numbers-rows"><span></span></span></code></pre>
                      <div class="toolbar">
                       <div class="toolbar-item">
                        <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                       </div>
                      </div>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="veeam-text  " data-component="VeeamTextComponent">
                      <p><i>Example:</i></p>
                      <pre>Get-FileHash -Path 'C:\Program Files\Veeam\Veeam ONE\Veeam ONE Reporter Server\Veeam.Reporter.PackInstaller.dll' -Algorithm SHA1
</pre>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                    <div class=" veeam-component__component-spacing-below--ss">
                     <div class="veeam-text  " data-component="VeeamTextComponent">
                      <h4><b>Automated Hotfix Deployment Validator</b></h4>
                      <p>The following script has been developed to provide customers a quick way to check which version of Veeam ONE is presently installed and whether the hotfix has been deployed.</p>
                     </div>
                    </div>
                   </div>
                   <div class="expander-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="expander  veeam-component__component-spacing-below--lg" data-component="ExpanderComponent" data-config="{
            &quot;isTurnOffGaEvents&quot;: &quot;true&quot;,
            &quot;eventLabel&quot;: &quot;Click to expand and view PowerShell script.&quot;,
            &quot;eventCategory&quot;: &quot;How-to videos&quot;
         }">
                     <details class="expander__container expander__container--hide-borders">
                      <summary class="expander__title"> <span> Click to expand and view PowerShell script. </span> </summary>
                      <div class="expander__content">
                       <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                        <div class="code-block aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                         <div class="code-block  veeam-component__component-spacing-below--ss" data-component="CodeBlockComponent">
                          <div class="code-toolbar">
                           <pre class="line-numbers language-powershell"><code class="language-powershell"><span class="token comment">#Display Installed Veeam ONE Version</span><br><span class="token function">Write-Host</span> <span class="token string">"Checking for installed Veeam ONE..."</span>`n<br><span class="token variable">$veeamOnePackage</span> = <span class="token function">Get-Package</span> <span class="token operator">-</span>ProviderName msi <span class="token punctuation">|</span> <span class="token function">Where-Object</span> <span class="token punctuation">{</span> <span class="token variable">$_</span><span class="token punctuation">.</span>Name <span class="token operator">-eq</span> <span class="token string">"Veeam ONE Reporter Server"</span> <span class="token punctuation">}</span><br><span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token variable">$null</span> <span class="token operator">-eq</span> <span class="token variable">$veeamOnePackage</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>    <span class="token function">Write-Host</span> <span class="token string">"Veeam ONE does not appear to be installed on this machine."</span>`n <span class="token operator">-</span>ForegroundColor Red<br>	<span class="token keyword">BREAK</span><br><span class="token punctuation">}</span> <span class="token keyword">else</span> <span class="token punctuation">{</span><br>    <span class="token variable">$installedVersion</span> = <span class="token variable">$veeamOnePackage</span><span class="token punctuation">.</span>Version<br>    <span class="token function">Write-Host</span> <span class="token string">"The following Veeam ONE Build is installed: <span class="token variable">$installedVersion</span>"</span>`n <span class="token operator">-</span>ForegroundColor Green<br><br>		<span class="token comment"># If the installed version is 12.0.0.2498 and display an update message and terminate.</span><br>		<span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token variable">$installedVersion</span> <span class="token operator">-eq</span> <span class="token string">"12.0.0.2498"</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>			<span class="token function">Write-Host</span> <span class="token string">"ERROR: Installed Veeam ONE build is 12.0.0.2498, update to build 12.0.1.2591 is required. See KB4430"</span>`n <span class="token operator">-</span>ForegroundColor Red<br>		<span class="token keyword">BREAK</span><br>		<span class="token punctuation">}</span><br><span class="token punctuation">}</span><br><br><span class="token comment"># Define Veeam ONE Reporter Server Root Folder</span><br><span class="token variable">$installLocation</span> = <span class="token variable">$veeamOnePackage</span><span class="token punctuation">.</span>Source    <br><span class="token variable">$rootFolder</span> = <span class="token function">Join-Path</span> <span class="token operator">-</span>Path <span class="token variable">$installLocation</span> <span class="token operator">-</span>ChildPath <span class="token string">"Veeam ONE Reporter Server\"</span><br><br><span class="token comment"># List of files to check</span><br><span class="token variable">$fileList</span> = @<span class="token punctuation">(</span><br>    <span class="token string">"Veeam.Reporter.GrpcService.dll"</span><span class="token punctuation">,</span><br>    <span class="token string">"Veeam.Reporter.WebApiService.dll"</span><span class="token punctuation">,</span><br>    <span class="token string">"Veeam.Reporter.PackInstaller.dll"</span><span class="token punctuation">,</span><br>    <span class="token string">"Veeam.Reporter.GrpcShared.dll"</span><span class="token punctuation">,</span><br>    <span class="token string">"Collecting\Veeam.Retriever.exe"</span><span class="token punctuation">,</span><br>    <span class="token string">"Collecting\Veeam.Reporter.GrpcShared.dll"</span><span class="token punctuation">,</span><br>    <span class="token string">"Reporting\Veeam.Reporter.Reporting.exe"</span><span class="token punctuation">,</span><br>    <span class="token string">"Reporting\Veeam.Reporter.GrpcShared.dll"</span><br><span class="token punctuation">)</span><br><br><span class="token comment"># Dictionary of known file hash values</span><br><span class="token variable">$hashList</span> = @<span class="token punctuation">{</span><br>    <span class="token string">"Veeam.Reporter.GrpcService.dll"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"269AFC1424BC58612AC97B08520473FEEF518D4A"</span><span class="token punctuation">,</span> <span class="token string">"B6B4404D50817EB73927F211A570767D6A0D3DE0"</span><span class="token punctuation">,</span> <span class="token string">"990A1BAB5C408DC2CB53B2637E4FABCBDB943E96"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Veeam.Reporter.WebApiService.dll"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"4406F2F4F6D7F07811946D2637DD8BB8322E91E0"</span><span class="token punctuation">,</span> <span class="token string">"28A7D7411EF41E939D1B8D6F669966EDB1C61B12"</span><span class="token punctuation">,</span> <span class="token string">"1957C5C23C89348A9F0B9405CECC3C2985F858BB"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Veeam.Reporter.PackInstaller.dll"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"B02B20BB6E45E7E9DB2D68E8FDDAADF0ADA4BCF5"</span><span class="token punctuation">,</span> <span class="token string">"CEB6EFCCB4CCA079501BE7A6DA225F2126761044"</span><span class="token punctuation">,</span> <span class="token string">"717F85C39D2FAB41D720ABDDAB69B03C3AAD5ADD"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Veeam.Reporter.GrpcShared.dll"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"F0ADE6C781D673B9DB84F14AD0C2D0BE847873BD"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Collecting\Veeam.Retriever.exe"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"8FCA25B1CD81D89E3B0A977B8AF5255487610969"</span><span class="token punctuation">,</span> <span class="token string">"21D989ACF3AA191079D40FDAE06AE1B8AFBC9C8F"</span><span class="token punctuation">,</span> <span class="token string">"AE9EE91C786D097F65B8CB26CCA253E1B4724C2C"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Collecting\Veeam.Reporter.GrpcShared.dll"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"AC5A2945728E8C60BCF4E879BCAC6B235F38B5B3"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Reporting\Veeam.Reporter.Reporting.exe"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"D1EC3C8E25C654106481F7DF9281BB271461E7AD"</span><span class="token punctuation">,</span> <span class="token string">"7359FE86A6160EF1C0C9CA913E7216DA622D6F32"</span><span class="token punctuation">,</span> <span class="token string">"DDBE4199AA973CDD71A4F3A68B5B68CD109BFF1D"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br>    <span class="token string">"Reporting\Veeam.Reporter.GrpcShared.dll"</span> = @<span class="token punctuation">{</span><br>        <span class="token string">"SHA1"</span> = @<span class="token punctuation">(</span><span class="token string">"827E1929916972E6ABA25DDA15F0CD5474EBBFB8"</span><span class="token punctuation">)</span><br>    <span class="token punctuation">}</span><br><span class="token punctuation">}</span><br><br><span class="token comment"># Creat array to store table data</span><br><span class="token variable">$tableData</span> = @<span class="token punctuation">(</span><span class="token punctuation">)</span><br><br><span class="token comment"># Check files and collect data for the table</span><br><span class="token keyword">foreach</span> <span class="token punctuation">(</span><span class="token variable">$file</span> in <span class="token variable">$fileList</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>	<span class="token comment"># Skip checking Veeam.Reporter.GrpcShared.dll for builds 11.0.1.1880 or 11.0.0.1379 as that file was only relevant to 12.0.1.2591.</span><br>	<span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token variable">$file</span> <span class="token operator">-like</span> <span class="token string">"*Veeam.Reporter.GrpcShared.dll"</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>		<span class="token variable">$fileVersion</span> = <span class="token punctuation">(</span><span class="token function">Get-Item</span> <span class="token punctuation">(</span><span class="token function">Join-Path</span> <span class="token operator">-</span>Path <span class="token variable">$rootFolder</span> <span class="token operator">-</span>ChildPath <span class="token variable">$file</span><span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">.</span>VersionInfo<span class="token punctuation">.</span>FileVersion<br>		<span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token variable">$fileVersion</span> <span class="token operator">-eq</span> <span class="token string">"11.0.0.1379"</span> <span class="token operator">-or</span> <span class="token variable">$fileVersion</span> <span class="token operator">-eq</span> <span class="token string">"11.0.1.1880"</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>			<span class="token keyword">continue</span><br>		<span class="token punctuation">}</span><br>	<span class="token punctuation">}</span><br><br>	<span class="token variable">$filePath</span> = <span class="token function">Join-Path</span> <span class="token operator">-</span>Path <span class="token variable">$rootFolder</span> <span class="token operator">-</span>ChildPath <span class="token variable">$file</span><br>	<span class="token variable">$fileDetails</span> = <span class="token variable">$hashList</span><span class="token punctuation">[</span><span class="token variable">$file</span><span class="token punctuation">]</span><br><br>	<span class="token comment"># identify file version and determine SHA1 hash</span><br>	<span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token function">Test-Path</span> <span class="token variable">$filePath</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>		<span class="token variable">$fileVersion</span> = <span class="token punctuation">(</span><span class="token function">Get-Item</span> <span class="token variable">$filePath</span><span class="token punctuation">)</span><span class="token punctuation">.</span>VersionInfo<span class="token punctuation">.</span>FileVersion<br>		<span class="token variable">$fileSHA1</span> = <span class="token function">Get-FileHash</span> <span class="token operator">-</span>Path <span class="token variable">$filePath</span> <span class="token operator">-</span>Algorithm SHA1 <span class="token punctuation">|</span> <span class="token function">Select-Object</span> <span class="token operator">-</span>ExpandProperty Hash<br>		<span class="token variable">$hashVerified</span> = <span class="token boolean">$false</span><br><br>		<span class="token comment"># compare file on disk hash to known hotfix hash values</span><br>		<span class="token keyword">foreach</span> <span class="token punctuation">(</span><span class="token variable">$hash</span> in <span class="token variable">$fileDetails</span><span class="token punctuation">.</span>SHA1<span class="token punctuation">)</span> <span class="token punctuation">{</span><br>			<span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token variable">$fileSHA1</span> <span class="token operator">-eq</span> <span class="token variable">$hash</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br>				<span class="token variable">$hashVerified</span> = <span class="token boolean">$true</span><br>				<span class="token keyword">break</span><br>			<span class="token punctuation">}</span><br>		<span class="token punctuation">}</span><br>	<span class="token punctuation">}</span> <span class="token keyword">else</span> <span class="token punctuation">{</span><br>		<span class="token variable">$fileVersion</span> = <span class="token string">"N/A"</span><br>		<span class="token variable">$hashVerified</span> = <span class="token boolean">$false</span><br>	<span class="token punctuation">}</span><br><br>	<span class="token comment"># Create an object for each file and add it to the table data array</span><br>	<span class="token variable">$fileData</span> = <span class="token namespace">[PSCustomObject]</span>@<span class="token punctuation">{</span><br>		FileName = <span class="token variable">$file</span><br>		Version = <span class="token variable">$fileVersion</span><br>		<span class="token string">"HotFix Installed"</span> = <span class="token variable">$hashVerified</span><br>	<span class="token punctuation">}</span><br>	<span class="token variable">$tableData</span> <span class="token operator">+=</span> <span class="token variable">$fileData</span><br><span class="token punctuation">}</span><br><br><span class="token comment"># Display the table</span><br><span class="token variable">$tableData</span> <span class="token punctuation">|</span> <span class="token function">Format-Table</span> <span class="token operator">-</span>AutoSize<br><span class="line-numbers-rows"><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span><span></span></span></code></pre>
                           <div class="toolbar">
                            <div class="toolbar-item">
                             <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                            </div>
                           </div>
                          </div>
                         </div>
                        </div>
                       </div>
                      </div>
                     </details>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
             <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
              <div class=" veeam-component__component-spacing-below--sm">
               <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
                <div class="bg-image-size-contain bg-image-position-left      ">
                 <div class="  " style="max-width: 100%;">
                  <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                   <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                    <span class="anchor" id="moreinfo"></span>
                   </div>
                   <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                    <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                     <div class="section-title__title-block">
                      <h2 class="section-title__title">More Information</h2>
                     </div>
                    </div>
                   </div>
                   <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                    <div class=" veeam-component__component-spacing-below--lg">
                     <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                      <p>The vulnerabilities associated with CVE-2023-38547, CVE-2023-38548, and CVE-2023-38549 were reported by <a href="https://hackerone.com/putsi?type=user" target="_blank" rel="noopener">Jarmo Puttonen<i>(@putsi)</i></a>.<br></p>
                      <p>&nbsp;</p>
                     </div>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
         </div>
        </div>
        <div class="side-navigation-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--phone--hide aem-GridColumn--default--none aem-GridColumn--phone--12 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--default--3 aem-GridColumn--offset--default--0 aem-GridColumn--tablet--hide">
         <nav class="side-navigation" data-component="SideNavigationComponent">
          <ul class="side-navigation__list">
           <li class="side-navigation__item"><a class="side-navigation__item-link" href="#details">Issue Details</a></li>
           <li class="side-navigation__item"><a class="side-navigation__item-link" href="#solution">Solution</a></li>
           <li class="side-navigation__item"><a class="side-navigation__item-link" href="#downloadinfo">├ Download Information</a></li>
           <li class="side-navigation__item"><a class="side-navigation__item-link" href="#deployinfo">├ Deployment Information</a></li>
           <li class="side-navigation__item"><a class="side-navigation__item-link" href="#validate">├ Deployment Validation</a></li>
           <li class="side-navigation__item"><a class="side-navigation__item-link" href="#moreinfo">More Information</a></li>
          </ul>
          <div class="side-navigation__indicator"></div>
         </nav>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Security Issue in Microsoft Azure Plug-In for Veeam Backup & Replication]]></title>
 <link href="https://www.veeam.com/kb4491"/> 
 <id>https://www.veeam.com/kb4491</id>
 <updated>2023-09-07T00:00:00Z</updated>
 <published>2023-09-07T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup & Replication]]></name>
 </author>
 <summary><![CDATA[This security issue may allow a user to obtain the administrator credentials of the Veeam Backup for Microsoft Azure appliance if that appliance was upgraded to version 5a.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title center 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Security Issue in Microsoft Azure Plug-In for Veeam Backup &amp; Replication</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4491</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup &amp; Replication | 12</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2023-09-07</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2023-09-07</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Issue Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>This article highlights a security-related issue in&nbsp;<a href="https://www.veeam.com/backup-replication-vcp-download.html?tab=cloud-plugins" target="_blank" rel="noopener">Microsoft Azure Plug-In for Veeam Backup &amp; Replication</a> 12.1.5.99 that may allow a user accessing the Veeam Backup &amp; Replication server to obtain the administrator credentials of the Veeam Backup <i>for Microsoft Azure</i> backup appliance, potentially allowing an attacker to gain access to the Veeam Backup <i>for Microsoft Azure</i> appliance.</p>
                  <p>This issue explicitly affects any environment where an <b>existing </b>deployment of Veeam Backup <i>for Microsoft Azure</i> was <a href="https://helpcenter.veeam.com/docs/vbazure/vbr_integration/upgrade_vb_5a.html?ver=5a" target="_blank" rel="noopener">upgraded to version 5a</a> while using Microsoft Azure Plug-In for Veeam Backup &amp; Replication version 12.1.5.99. During the appliance upgrade process, administrator credentials were requested to update the Veeam Backup <i>for Microsoft Azure</i> backup appliance's operating system from Ubuntu 18.04 LTS to Ubuntu 22.04 LTS. That Veeam Backup <i>for Microsoft Azure</i> backup appliance administrator password was stored in the Updater log file: <i>C:\ProgramData\Veeam\Backup\Plugins\Microsoft Azure\Logs\&lt;backup_appliance_name&gt;\Veeam.Azure.Updater</i>.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--md">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>To address this issue, Veeam has released a new build of Microsoft Azure Plug-In for Veeam Backup &amp; Replication.</p>
                   <p><b>It is advised to install this update as soon as possible.</b></p>
                   <p><b>Issue fixed starting in:</b>&nbsp;Microsoft Azure Plug-In for Veeam Backup &amp; Replication 12.1.5.106</p>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class=" veeam-component__component-spacing-below--lg">
                  <div class="veeam-text  " data-component="VeeamTextComponent">
                   <h4><b>Update Procedure</b></h4>
                   <ol>
                    <li>Obtain Microsoft Azure Plug-In for Veeam Backup &amp; Replication 12.1.5.106. 
                     <ul>
                      <li><a href="https://www.veeam.com/backup-replication-vcp-download.html?tab=cloud-plugins" target="_blank" rel="noopener">Cloud Plugins Download Page</a></li>
                      <li><a href="https://www.veeam.com/download_add_packs/vmware-esx-backup/azureplugin/" target="_blank" rel="noopener">Direct Link to Download Latest&nbsp;Microsoft Azure Plug-In for Veeam Backup &amp; Replication</a></li>
                     </ul></li>
                    <li><a href="https://helpcenter.veeam.com/docs/vbazure/vbr_integration/uninstall_plugin.html?ver=5a" target="_blank" rel="noopener">Uninstall Microsoft Azure Plug-In for Veeam Backup &amp; Replication</a> 12.1.5.99.</li>
                    <li><a href="https://helpcenter.veeam.com/docs/vbazure/vbr_integration/deploy_plugin.html?ver=5a" target="_blank" rel="noopener">Install Microsoft Azure Plug-In for Veeam Backup &amp; Replication</a> 12.1.5.106.</li>
                    <li>Update the password for the account used by Veeam Backup &amp; Replication to connect to Veeam Backup <i>for Microsoft Azure</i>. 
                     <ol type="a">
                      <li><a href="https://helpcenter.veeam.com/docs/vbazure/guide/changing_password.html?ver=5a" target="_blank" rel="noopener">Update the password in Veeam Backup <i>for Microsoft Azure</i></a> first.</li>
                      <li>Then,&nbsp;<a href="https://helpcenter.veeam.com/docs/vbazure/vbr_integration/connect_appliance_creds.html?ver=5a" target="_blank" rel="noopener">update the password within Veeam Backup &amp; Replication</a>.<br></li>
                     </ol></li>
                   </ol>
                   <p>When version 12.1.5.106 of the Plug-In is installed, the Plug-In will replace the backup appliance administrator password in the existing updater log files with asterisks (*). During future update procedures, the Plug-In will log only asterisks (*) instead of the actual Veeam Backup <i>for Microsoft Azure</i> backup appliance administrator password.</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Veeam Backup for Google Cloud - Critical Vulnerability (CVE-2022-43549)]]></title>
 <link href="https://www.veeam.com/kb4374"/> 
 <id>https://www.veeam.com/kb4374</id>
 <updated>2022-11-08T00:00:00Z</updated>
 <published>2022-11-08T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup for Google Cloud]]></name>
 </author>
 <summary><![CDATA[During internal testing, a vulnerability was discovered within the Backup Appliance component of Veeam Backup for Google Cloud that allows users to bypass authentication mechanisms. A fix has been released to resolve the discovered vulnerability in Veeam Backup for Google Cloud versions 1 and 3. For most users, no actions will be needed, as the Veeam Updater component will have automatically installed this fix during its daily check for updates1.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Veeam Backup <i>for Google Cloud</i> - Critical Vulnerability (CVE-2022-43549)</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4374</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup <i>for Google Cloud</i> | 1.0 | 3.0</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2022-11-08</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-03-28</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__title">
               Automatic Patching of Components
              </div>
              <div class="notice__text veeam-text">
               <p>The fix for the vulnerability discussed in this article has been automatically deployed to all Veeam Backup <i>for Google Cloud</i> Backup Appliances that have been configured to have <a href="https://helpcenter.veeam.com/docs/vbazure/guide/ports.html#:~:text=repository.veeam.com" target="_blank" rel="noopener">access to repository.veeam.com</a>. Most users will have no additional actions to perform beyond confirming the Veeam Updater component version.</p>
               <p><b>For deployments where the Veeam Backup <i>for Google Cloud</i> Backup Appliance does <u>not</u>&nbsp;have network access to the Veeam Update Repository, the fix must be <a href="#moreinfo" target="_self">deployed manually</a>.</b></p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Vulnerability Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>During internal testing, a vulnerability was discovered within the Backup Appliance component of <b>Veeam Backup <i>for Google Cloud</i>&nbsp;</b>that allows users to bypass authentication mechanisms.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b>CVSS v3 Score:</b> 10.0<br><b>Status:</b> Resolved</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--sm">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   A fix has been released to resolve the discovered vulnerability in Veeam Backup <i>for Google Cloud</i> versions 1 and 3. <b>For most users, no actions will be needed</b>, as the Veeam Updater component will have automatically installed this fix during its daily check for updates<sup><a href="#moreinfo" target="_self">1</a></sup>. After the fix has been installed, the Backup Appliance will be restarted automatically. For environments where the Veeam Backup <i>for Google Cloud</i> backup appliance does not have access to <i>repository.veeam.com,</i> the fix will have to be manually deployed<sup><a href="#moreinfo" target="_self">2</a></sup>&nbsp;or internet access configured to <a href="https://helpcenter.veeam.com/docs/vbgc/guide/ports.html?zoom_highlight=repository.veeam.com&amp;ver=30" target="_blank" rel="noopener">allow access to the update server</a>.
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                 <span class="anchor" id="verifyupdate"></span>
                </div>
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Verify Update Deployment</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--sm">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   The fix for the vulnerability documented in this article is being shipped alongside Veeam Updater version 6.0.0.814 and higher. 
                   <br>
                    The Veeam Updater component version is displayed in the top-right of the&nbsp;<a href="https://helpcenter.veeam.com/docs/vbgc/guide/updates_check.html?ver=30" target="_blank" rel="noopener">web interface</a>.<a href="#moreinfo" target="_self"><sup>3</sup></a>
                  </div>
                 </div>
                </div>
                <div class="image aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="veeam-image veeam-image--align-center      veeam-component__component-spacing-below--md" data-component="VeeamImageComponent">
                  <div class="veeam-image__view" itemscope itemtype="http://schema.org/ImageObject">
                   <link itemprop="license acquireLicensePage" href="https://www.veeam.com/privacy-notice.html">
                   <meta itemprop="copyrightNotice" content="© Veeam® Software">
                   <meta itemprop="description" content="Patch Version">
                   <meta itemprop="creditText" content="Veeam Software"><span itemscope itemprop="creator" itemtype="https://schema.org/organization">
                    <meta itemprop="name" content="Veeam Software"></span> <picture>
                    <source media="(max-width: 480px)" srcset="https://cdn.veeam.com/content/veeam/en/knowledge-base/kb4374/_jcr_content/content-parsys/section-main/section-with-background-content/section-sections/section-with-background-content/section_with_backgro_1377495372/section-with-background-content/image/file.web.ntfile.png/Patch.png?ck=1667424771116">
                    <source media="(max-width: 960px)" srcset="https://cdn.veeam.com/content/veeam/en/knowledge-base/kb4374/_jcr_content/content-parsys/section-main/section-with-background-content/section-sections/section-with-background-content/section_with_backgro_1377495372/section-with-background-content/image/file.web.ntfile.png/Patch.png?ck=1667424771116">
                    <img class="veeam-image__image" src="https://cdn.veeam.com/content/veeam/en/knowledge-base/kb4374/_jcr_content/content-parsys/section-main/section-with-background-content/section-sections/section-with-background-content/section_with_backgro_1377495372/section-with-background-content/image/file.web.ntfile.png/Patch.png?ck=1667424771116" loading="lazy" itemprop="contentUrl" style="aspect-ratio:auto;" alt="Patch Version" title="Shown above is the location of the Veeam Updater component version.">
                   </picture> <span class="veeam-image__caption" itemprop="caption">
                    <div style="text-align: center;">
                     Shown above is the location of the Veeam Updater component version.
                     <br>
                    </div></span>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                 <span class="anchor" id="moreinfo"></span>
                </div>
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p><sup>1&nbsp;</sup>The Veeam Updater checks for updates every 24 hours. The Veeam Updater will automatically install updates to the Veeam Updater component and critical updates for other components.</p>
                   <p><sup>2</sup> The update check requires that the Veeam Backup <i>for Google Cloud</i> backup appliance have internet access and be able to reach&nbsp;<i>repository.veeam.com</i> as documented in the <a href="https://helpcenter.veeam.com/docs/vbgc/guide/ports.html?zoom_highlight=repository.veeam.com" target="_blank" rel="noopener">product user guide</a>.&nbsp;<b>If the Veeam Backup <i>for Google Cloud</i> backup appliance does not have internet access, a manual update process is available. Please contact&nbsp;<a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">Veeam Support</a>&nbsp;for assistance.</b> After manual updating, the Updater UI will have to be reopened to see the updated version listed.<br></p>
                   <p><sup>3</sup> If the Veeam Updater UI is opened before it has updated automatically, clicking "Check for Updates..." will cause the Veeam Updater UI to download the update and become inaccessible while the Backup Appliance is automatically restarted to apply the fix. After reopening the Veeam Updater, the new version number will be displayed.<br></p>
                   <p>&nbsp;</p>
                   <p>&nbsp;</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[XSS Vulnerability in Veeam Management Pack for Microsoft System Center v8]]></title>
 <link href="https://www.veeam.com/kb4338"/> 
 <id>https://www.veeam.com/kb4338</id>
 <updated>2022-07-12T00:00:00Z</updated>
 <published>2022-07-12T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Management Pack for Microsoft System Center]]></name>
 </author>
 <summary><![CDATA[A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft System Center 8.0. This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack for Microsoft System Center server, allowing for the execution of arbitrary scripts.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
  <div class="bg-image-size-contain bg-image-position-left   ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">XSS Vulnerability in Veeam Management Pack <i>for Microsoft System Center</i> v8</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
        <div class="bg-image-size-contain bg-image-position-left   ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4338</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Management Pack | 8.0</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2022-07-12</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2022-07-12</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #b0b0b0;">
       <div class="bg-image-size-contain bg-image-position-left   ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--lg">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-center      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Vulnerability Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack <i>for Microsoft System Center</i> 8.0.</p>
                  <p>This vulnerability could be exploited by an attacker by convincing a legitimate user to visit a crafted URL on a Veeam Management Pack <i>for Microsoft System Center</i> server, allowing for the execution of arbitrary scripts.</p>
                  <p>&nbsp;</p>
                  <p><b>CVE:</b>&nbsp;CVE-2022-32225</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--lg">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-center      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  <p>Veeam Management Pack <i>for Microsoft System Center</i> 8.0 has reached <a href="https://www.veeam.com/product-lifecycle.html" target="_blank" rel="noopener"><b>End-of-Fix</b></a>, and all users are advised to <b>upgrade to the <a href="https://www.veeam.com/vmware-microsoft-esx-monitoring-download.html" target="_blank" rel="noopener">latest version of Veeam Management Pack <i>for Microsoft System Center</i></a></b>.</p>
                  <p>This vulnerability does&nbsp;<b><u>not</u>&nbsp;</b>affect Veeam Management Pack <i>for Microsoft System Center</i> version 9.0.</p>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--lg">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-center      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Temporary mitigation</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>If upgrading to the latest version of Veeam Management Pack <i>for Microsoft System Center</i> is not possible, this vulnerability can be mitigated by removing the Help directory.</p>
                   <p>Default location:</p>
                  </div>
                 </div>
                </div>
                <div class="code-block aem-GridColumn aem-GridColumn--default--12">
                 <div class="code-block  veeam-component__component-spacing-below--ss" data-component="CodeBlockComponent">
                  <div class="code-toolbar">
                   <pre class="line-numbers language-none"><code class="language-none">C:\Program Files (x86)\Veeam\Veeam Virtualization Extensions for System Center\User Interface\Help<span class="line-numbers-rows"><span></span></span></code></pre>
                   <div class="toolbar">
                    <div class="toolbar-item">
                     <button class="copy-to-clipboard-button" type="button" data-copy-state="copy"><span>Copy</span></button>
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--lg">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-center      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                  This vulnerability was reported by&nbsp;Mateusz Dabrowski. 
                  <br>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #b0b0b0; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
<entry>
 <title><![CDATA[Veeam Backup for Microsoft Azure - Updater Component Vulnerability]]></title>
 <link href="https://www.veeam.com/kb4261"/> 
 <id>https://www.veeam.com/kb4261</id>
 <updated>2022-01-06T00:00:00Z</updated>
 <published>2022-01-06T00:00:00Z</published>
 <author>
     <name type="html"><![CDATA[Veeam Backup for Microsoft Azure]]></name>
 </author>
 <summary><![CDATA[A vulnerability has been found in Veeam Backup for Microsoft Azure that may allow users to bypass authentication and execute arbitrary code. A hotfix is now available.]]></summary>
 <content type="html"><![CDATA[<div class=" veeam-component__component-spacing-below--lgx">
 <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
  <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
   <div class="section__container--centered section__container-spacing--md " style="max-width: 1260px;">
    <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
     <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
      <div class="section-title center 
            section-title--only-title  ">
       <div class="section-title__title-block">
        <h1 class="section-title__title">Veeam Backup for Microsoft Azure - Updater Component Vulnerability</h1>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class=" veeam-component__component-spacing-below--md">
       <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
        <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
         <div class="  " style="max-width: 100%;">
          <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
           <div class="knowledge-base-details aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--6 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
            <div class="knowledge-base-details__container" data-component="KBDetailsComponent">
             <a class="knowledge-base-details__print-button no-print" href="javascript:void(0);" title="Print page"> <i class="v-icon fa-solid fa-print"></i> </a>
             <table class="knowledge-base-details__table">
              <tbody>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">KB ID:</td>
                <td class="knowledge-base-details__value">4261</td>
               </tr>
               <tr class="knowledge-base-details__row">
                <td class="knowledge-base-details__label">Product:</td>
                <td class="knowledge-base-details__value">Veeam Backup <i>for Microsoft Azure</i> | 2.0 | 3.0</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Published:</td>
                <td class="knowledge-base-details__value">2022-01-06</td>
               </tr>
               <tr class="knowledge-base-details__row rss-feed-remove__row">
                <td class="knowledge-base-details__label">Last Modified:</td>
                <td class="knowledge-base-details__value">2025-03-17</td>
               </tr>
              </tbody>
             </table>
            </div>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
     <div class="section-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn--default--9 aem-GridColumn aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
      <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
       <div class="bg-image-size-contain bg-image-position-center bg-image-hide-mobile bg-image-hide-tablet ">
        <div class="section__container--centered  " style="max-width: 100%;">
         <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
          <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
            <div class="notice notice--success">
             <div class="notice__icon">
              <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
             </div>
             <div class="notice__content">
              <div class="notice__title">
               Automatic Patching of Veeam Updater component
              </div>
              <div class="notice__text veeam-text">
               <p>The fix for the vulnerability discussed in this article has been automatically deployed to all Veeam Backup for Microsoft Azure backup appliances that have been configured to have <a href="https://helpcenter.veeam.com/docs/vbazure/guide/ports.html#:~:text=repository.veeam.com" target="_blank" rel="noopener">access to repository.veeam.com</a>. Most users will have no additional actions to perform beyond confirming the Veeam Updater component version.</p>
               <p><b>For deployments where the Veeam Backup for Microsoft Azure backup appliance does <u>not</u>&nbsp;have internet access to the Veeam update server, the fix must be <a href="#moreinfo" target="_self">deployed manually</a>.</b></p>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Vulnerability Details</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>During internal testing, a vulnerability was discovered within the Veeam Updater component of <b>Veeam Backup for Microsoft Azure </b>that allows users to bypass authentication mechanisms and execute arbitrary code.<br>
                     At this time, there is no evidence that this has been exploited in the wild.</p>
                   <p><b>Severity:</b>&nbsp;Critical<br><b><a href="https://www.first.org/cvss/user-guide" target="_blank" rel="noopener">CVSS v3 Score</a>:</b> 10.0<br><b>Status:</b> Resolved</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--tablet--12 aem-Grid--default--12 aem-Grid--phone--12 ">
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">Solution</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--sm">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p>A fix has been released to resolve the discovered vulnerability in Veeam Backup for Microsoft Azure versions 2 and 3. <b>For most users, no actions will be needed</b>, as the Veeam Updater component will have automatically installed this fix during its daily check for updates<sup><a href="#moreinfo" target="_self">1</a></sup>. However, for environments where the Veeam Backup for Microsoft Azure backup appliance does not have access to <i>repository.veeam.com,</i> the fix will have to be manually deployed<sup><a href="#moreinfo" target="_self">2</a></sup>&nbsp;or internet access configured to <a href="https://helpcenter.veeam.com/docs/vbazure/guide/ports.html#:~:text=repository.veeam.com" target="_blank" rel="noopener">allow access to the update server</a>.</p>
                   <p>The Veeam Updater component version is displayed in the top-right of the&nbsp;<a href="https://helpcenter.veeam.com/docs/vbazure/guide/updates_check.html" target="_blank" rel="noopener">web interface</a>.<a href="#moreinfo" target="_self"><sup>3</sup></a><br>
                     The vulnerability documented in this article is corrected starting in Veeam Updater version&nbsp;<b>5.0.0.633</b>.</p>
                  </div>
                 </div>
                </div>
                <div class="image aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="veeam-image veeam-image--align-center      veeam-component__component-spacing-below--sm" data-component="VeeamImageComponent">
                  <div class="veeam-image__view" itemscope itemtype="http://schema.org/ImageObject">
                   <link itemprop="license acquireLicensePage" href="https://www.veeam.com/privacy-notice.html">
                   <meta itemprop="copyrightNotice" content="© Veeam® Software">
                   <meta itemprop="description" content="Shown in screenshot of hotfixed version of Veeam Updater version">
                   <meta itemprop="creditText" content="Veeam Software"><span itemscope itemprop="creator" itemtype="https://schema.org/organization">
                    <meta itemprop="name" content="Veeam Software"></span> <picture>
                    <source media="(max-width: 480px)" srcset="https://cdn.veeam.com/content/veeam/en/knowledge-base/kb4261/_jcr_content/content-parsys/section-main/section-with-background-content/section-sections/section-with-background-content/section_with_backgro_solution/section-with-background-content/image/file.web.ntfile.png/PatchedVersion.png?ck=1640883461344">
                    <source media="(max-width: 960px)" srcset="https://cdn.veeam.com/content/veeam/en/knowledge-base/kb4261/_jcr_content/content-parsys/section-main/section-with-background-content/section-sections/section-with-background-content/section_with_backgro_solution/section-with-background-content/image/file.web.ntfile.png/PatchedVersion.png?ck=1640883461344">
                    <img class="veeam-image__image" src="https://cdn.veeam.com/content/veeam/en/knowledge-base/kb4261/_jcr_content/content-parsys/section-main/section-with-background-content/section-sections/section-with-background-content/section_with_backgro_solution/section-with-background-content/image/file.web.ntfile.png/PatchedVersion.png?ck=1640883461344" loading="lazy" itemprop="contentUrl" style="aspect-ratio:auto;" alt="Shown in screenshot of hotfixed version of Veeam Updater version" title="Shown above is the location of the Veeam Updater component version.">
                   </picture> <span class="veeam-image__caption" itemprop="caption">
                    <div style="text-align: center;">
                     <i>Shown above is the location of the Veeam Updater component version.</i>
                    </div></span>
                  </div>
                 </div>
                </div>
                <div class="notice-component parbase aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
                 <div class="notice-component--spacing  veeam-component__component-spacing-below--lg" data-component="NoticeComponent">
                  <div class="notice notice--success">
                   <div class="notice__icon">
                    <i class="v-icon fa-solid fa-circle-info"></i> <i class="v-icon fa-solid fa-bell"></i> <i class="v-icon fa-solid fa-triangle-exclamation"></i>
                   </div>
                   <div class="notice__content">
                    <div class="notice__text veeam-text">
                     This vulnerability <b>does not</b> affect Veeam Backup for AWS nor Veeam Backup for Google Cloud Platform.
                    </div>
                   </div>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="section-component parbase aem-GridColumn aem-GridColumn--default--12">
           <div class=" veeam-component__component-spacing-below--sm">
            <div class="section    " style="background-image: linear-gradient(180deg, transparent 0.0%, transparent 100.0%); border-color: #ADACAF;">
             <div class="bg-image-size-contain bg-image-position-left      ">
              <div class="  " style="max-width: 100%;">
               <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 ">
                <div class="anchor-component aem-GridColumn aem-GridColumn--default--12">
                 <span class="anchor" id="moreinfo"></span>
                </div>
                <div class="section-title-component aem-GridColumn aem-GridColumn--default--12">
                 <div class="section-title section-title--alignment-left 
            section-title--only-title  ">
                  <div class="section-title__title-block">
                   <h2 class="section-title__title">More Information</h2>
                  </div>
                 </div>
                </div>
                <div class="veeam-text text aem-GridColumn aem-GridColumn--default--12">
                 <div class=" veeam-component__component-spacing-below--ss">
                  <div class="veeam-text  veeam-text--adaptive-mode" data-component="VeeamTextComponent">
                   <p><sup>1&nbsp;</sup>The Veeam Updater checks for updates every 24 hours. The Veeam Updater will automatically install updates to the Veeam Updater component. Updates to components other than the Veeam Updater must be <a href="https://helpcenter.veeam.com/docs/vbazure/guide/updates_check.html" target="_blank" rel="noopener">applied by the user</a>.</p>
                   <p><sup>2</sup> The update check requires that the Veeam Backup for Microsoft Azure backup appliance have internet access and be able to reach&nbsp;<i>repository.veeam.com</i> as documented in the <a href="https://helpcenter.veeam.com/docs/vbazure/guide/ports.html?ver=30#:~:text=repository.veeam.com" target="_blank" rel="noopener">product user guide</a>.&nbsp;<b>If the Veeam Backup for Microsoft Azure backup appliance does not have internet access, a manual update process is available. Please contact&nbsp;<a href="https://www.veeam.com/kb1771" target="_blank" rel="noopener">Veeam Support</a>&nbsp;for assistance.</b> After manual updating, the Updater UI will have to be reopened to see the updated version listed.<br></p>
                   <p><sup>3</sup> If the Veeam Updater UI is opened before it has updated automatically, clicking "Update" will cause the Veeam Updater UI to download the update and become inaccessible until reopened. After reopening the Veeam Updater, the new version number will be displayed.<br></p>
                   <p>&nbsp;</p>
                   <p>&nbsp;</p>
                  </div>
                 </div>
                </div>
               </div>
              </div>
             </div>
            </div>
           </div>
          </div>
          <div class="horizontal-delimiter no-print aem-GridColumn--tablet--12 aem-GridColumn--offset--tablet--0 aem-GridColumn--default--none aem-GridColumn--phone--none aem-GridColumn--phone--12 aem-GridColumn--tablet--none aem-GridColumn aem-GridColumn--default--12 aem-GridColumn--offset--phone--0 aem-GridColumn--offset--default--0">
           <div class="delimiter  veeam-component__component-spacing-below--lgx">
            <div style="width: 100%; border-color: #ADACAF; border-width: 1px;"></div>
           </div>
          </div>
          <div class="veeam-text text no-print aem-GridColumn aem-GridColumn--default--12">
           <div class="veeam-text  " data-component="VeeamTextComponent">
            <p>If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a <a href="/kb1771">Veeam Support Case.</a></p>
            <p>To submit feedback regarding this article, please click this link: <span class="veeam-text__open-universal-form"><a href="?ad=in-text-link#kb_request_form">Send Article Feedback</a></span><br>
              To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.</p>
           </div>
          </div>
         </div>
        </div>
       </div>
      </div>
     </div>
    </div>
   </div>
  </div>
 </div>
</div>]]></content>
</entry>
</feed>