Saturday, November 16, 2024
HomeCVE/vulnerabilityVeeam RCE Flaws Let Hackers Gain Access To VSPC Servers

Veeam RCE Flaws Let Hackers Gain Access To VSPC Servers

Published on

Veeam Service Provider console has been discovered with two critical vulnerabilities that were associated with Remote Code Execution.

A CVE for these vulnerabilities is yet to be assigned. These vulnerabilities exist in version 7.x and version 8.x of the Veeam Service Provider Console.

Document

Free Webinar : Live API Attack Simulation

94% of organizations experience security problems in production APIs, and one in five suffers a data breach. As a result, cyber-attacks on APIs increased from 35% in 2022 to 46% in 2023, and this trend continues to rise:

- Advertisement - SIEM as a Service

Key Takeaways:

  • An exploit of OWASP API Top 10 vulnerability
  • A brute force ATO (Account Takeover) attack on API
  • A DDoS attack on an API
  • Positive security model automation to prevent API attacks

Start protecting your APIs from hackers

Veeam Service Provider Console is used for remote monitoring and management capabilities from a centralized user interface with API integrations.

However, the company has patched these vulnerabilities on their latest version release.

Veeam RCE Flaws

The Remote code execution vulnerabilities existed due to an unsafe deserialization method in the VSPC server communication between the management agent and its associated components. 

Threat actors can exploit this unsafe deserialization in a specific condition and achieve remote code execution on the VSPC server machine.

Along with fixing these RCE vulnerabilities, Veeam has also released several bug fixes and improvements on its products, such as new alarm triggers, improvements in public cloud integration, backup for Microsoft 365, and much more.

For VSPC 8 (build 8.0.0.16877), Veeam has informed the users to check their Veeam Service Provider Console’s version 8 before installing the cumulative patch. This can be checked in the backup portal by navigating to Configuration > Support.

As for VSPC 7, the advisory stated that the patch does not contain private fixes created after the release of P20230531 (7.0.0.14271). However, the cumulative patch was released only to address the Remote Code Execution security issue.

Additionally, the advisory also specified that Veeam Service Provider Console 7 has reached end fix in December 2023.

Further, users of these products are recommended to upgrade to the latest versions in order to prevent the exploitation of these vulnerabilities by threat actors.

Is Your Network Under Attack? - Read CISO’s Guide to Avoiding the Next Breach - Download Free Guide

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...