CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26501 +1 in the same advisory: …26500 | Unauthenticated RCE in Veeam Backup & Replication 10.x and 11.x CVE-2022-26501 is a critical (CVSS 9.8) missing-authentication/incorrect-access-control flaw in Veeam Backup & Replication 10.x and 11.x that allows unauthenticated remote code execution; it is one of two related flaws (CVE-2022-26500 and CVE-2022-26501) fixed together by Veeam. An attacker who can reach the affected backup service over the network can trigger the flaw without any credentials or user interaction and gain code execution with full confidentiality, integrity, and availability impact on the backup server. This hands attackers control of the backup infrastructure itself, which is valuable for harvesting stored credentials, tampering with or destroying backups, and moving laterally ahead of ransomware detonation. Any organization running Veeam Backup & Replication 10.x or 11.x is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-12-13 with known ransomware use, and public reporting associates these flaws with Cuba ransomware gang activity. Do: Apply Veeam's updates per vendor instructions to all 10.x and 11.x deployments and verify the patched build is installed on every backup server. Restrict network access to Veeam backup infrastructure (including any internet-exposed or cloud-facing Veeam services) to trusted management networks, and hunt for exploitation indicators given the known ransomware use. Because exploitation is in the wild, treat patching of Veeam backup servers as urgent and high priority. | 9.8 group max | 4% | KEV ransomware |
| mass≈10^5–10^6 backup server deployments (Veeam reports roughly 500k+ customers and 10.x/11.x were the then-current versions) |
Full article309 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 16, 2022Backup & Recovery / Zero-Day
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities impacting Veeam Backup & Replication software to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild.
The now-patched critical flaws, tracked as CVE-2022-26500 and CVE-2022-26501, are both rated 9.8 on the CVSS scoring system, and could be leveraged to gain control of a target system.
"The Veeam Distribution Service (TCP 9380 by default) allows unauthenticated users to access internal API functions," Veeam noted in an advisory published in March 2022. "A remote attacker may send input to the internal API which may lead to uploading and executing of malicious code."
Both the issues that impact product versions 9.5, 10, and 11 have been addressed in versions 10a and 11a. Users of Veeam Backup & Replication 9.5 are advised to upgrade to a supported version.
Nikita Petrov, a security researcher at Russian cybersecurity firm Positive Technologies, has been credited with discovering and reporting the weaknesses.
"We believe that these vulnerabilities will be exploited in real attacks and will put many organizations at significant risk," Petrov said on March 16, 2022. "That is why it is important to install updates as soon as possible or at least take measures to detect abnormal activity associated with these products."
Details on the attacks exploiting these vulnerabilities are unknown as yet, but cybersecurity company CloudSEK disclosed in October that it observed multiple threat actors advertising a "fully weaponized tool for remote code execution" that abuse the two flaws.
Some of the possible consequences of successful exploitation are infection with ransomware, data theft, and denial-of-service, making it imperative that users apply the updates.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html