HomeSecurityVeeam fixes serious vulnerabilities in Veeam ONE

Veeam patches critical vulnerabilities in Veeam ONE

Veeam has released emergency security patches to address four vulnerabilities in its IT infrastructure monitoring and analytics platform, Veeam ONE .

Veeam One vulnerabilities

Two of the vulnerabilities are critical. The company gave them CVSS scores of 9.8 and 9.9/10, as they allow attackers to execute code remotely (RCE) and steal NTLM hashes from vulnerable servers. The other two vulnerabilities are of medium severity and require user interaction or have limited impact.

“A vulnerability in Veeam ONE allows an unauthenticated user to obtain information about the SQL server connection that Veeam ONE uses to access its configuration database. This could lead to remote code execution on the SQL server hosting the Veeam ONE configuration database,” the company says about the vulnerability, which is tracked as CVE-2023-38547.

See also: The new CVSS 4.0 vulnerability severity rating standard has just been released

“A vulnerability in Veeam ONE allows an unprivileged user, with access to the Veeam ONE Web Client, to obtain the NTLM hash of the account used by the Veeam ONE Reporting Service,” the company says about the second critical vulnerability (CVE-2023-38548).

The third vulnerability ( CVE-2023-38549 ) could allow attackers with Power User roles to steal an administrator's access token in a Cross-Site Scripting (XSS) attack . This attack requires user interaction from someone with the Veeam ONE Administrator role.

Finally, the fourth vulnerability (CVE-2023-41723) that was fixed can be used by malicious users with Read-Only User role to access the Schedule Dashboard (the attacker cannot make changes).

According to the company, the above vulnerabilities affect supported versions of Veeam ONE up to the latest version. Veeam has released the following fixes:

  • Veeam ONE 12 P20230314 (12.0.1.2591)
  • Veeam ONE 11a (11.0.1.1880)
  • Veeam ONE 11 (11.0.0.1379)

Administrators must stop Veeam ONE monitoring and reporting services on affected servers, replace the files on disk with the files in the patch, and restart the services for the fixes to take effect.

See also: “Hello Kitty” Ransomware: Exploited Vulnerability in Open Source Apache ActiveMQ

Veeam patches critical vulnerabilities in Veeam ONE

In March, Veeam also patched a critical Backup Service (CVE-2023-27532) in its Backup & Replication. This vulnerability was used in attacks associated with the FIN7.

Months later, the ransomware Cuba gang also exploited the flaw to target critical infrastructure organizations in the United States and IT companies in Latin America.

Veeam says its software is used by more than 450,000 customers worldwide, many of whom are large and well-known companies.

The potential risks of not addressing these errors in a timely manner are multiple. First, the security of the system may be compromised, as these errors may provide opportunities for intrusion by malware or unwanted users. This can lead to loss data, privacy violations, or even loss of system functionality.

Furthermore, carelessness in handling these errors can lead to unpredictable system behaviors, which can affect its performance and reliability. This can have negative impacts on the business and its ability to provide services to customers .

See also: Atlassian: Warns of critical vulnerability in Confluence

Finally, failure to address errors can have legal consequences . If a company fails to protect its customers ' data or fails to address known errors in a timely manner, it could face lawsuits or fines.

Overall, failure to address critical errors in the Veeam ONE monitoring platform can have serious implications for security, performance, trust, and legal standing.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS