HomeUpdatesVeeam fixes vulnerabilities in Service Provider Console (VSPC)

Veeam patches vulnerabilities in Service Provider Console (VSPC)

Veeam has released security updates to fix two vulnerabilities in its Service Provider Console (VSPC).

Veeam Service Provider Console (VSPC) vulnerabilities

VSPC, a remotely-managed BaaS (Backend as a Service) and DRaaS (Disaster Recovery as a Service) platform, is used by service providers to monitor the health and security of customer backups and manage Veeam.

See also: Veeam fixes vulnerabilities in Backup & Replication (VBR)

The first vulnerability is tracked as CVE-2024-42448 and is considered critical (9.9/10), as it allows attackers to execute code on unpatched servers from the VSPC management agent machine.

The second vulnerability, CVE-2024-42449, could allow attackers to steal the NTLM hash of the VSPC server service account and use the access to delete files on the VSPC server.

The two VSPC vulnerabilities can only be successfully exploited if the management agent is authorized on the targeted server.

See also: Frag ransomware: Exploits Veeam vulnerability in attacks

The vulnerabilities affect VPSC 8.1.0.21377 and all previous versions, including builds 8 and 7, but unsupported product versions are likely affected as well.

“We encourage service providers using supported versions of Veeam Service Provider Console (versions 7 & 8) to apply the latest cumulative patch,” Veeam said.

Veeam patches vulnerabilities in Service Provider Console (VSPC)

“Service providers using unsupported versions are encouraged to upgrade to the latest version of Veeam Service Provider Console“.

See also: Akira and Fog ransomware exploit Veeam vulnerability 

The above vulnerabilities highlight the importance of timely application of security updates to mitigate risks in the ever-changing cybersecurity. It is vital for organizations to prioritize software updates. But there are other measures that organizations can take to protect themselves from similar vulnerabilities. These include regularly monitoring and reviewing system logs for any suspicious activity, implementing strict access control policies , and training employees to use security best practices. It is also important for companies to have a breach or security.

Veeam says its products are used by more than 550,000 customers worldwide, including very large companies.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS