ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Veeam fixes RCE flaw in backup management platform (CVE-2024-29212)

criticalVulnerability exploited in the wildimportance 60CVE-2024-29212CVE-2023-27532

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27532
Missing Authentication in Veeam Backup & Replication Exposes Stored Credentials

Veeam Backup & Replication (VBR) contains a missing-authentication flaw (CWE-306) in its Cloud Connect component that lets an unauthenticated network attacker obtain encrypted credentials stored in VBR's configuration database. It is triggered simply by connecting to the exposed service, because the function that serves credential material performs no authentication check; no privileges or user interaction are required (CVSS 3.1: 7.5, network vector). With the recovered credentials, an attacker can gain access to backup infrastructure hosts, which has been used as an entry point and pivot for ransomware operations. Any organization running Veeam Backup & Replication is potentially affected, with the greatest risk where the VBR/Cloud Connect service is reachable from the internet. Exploitation is confirmed: CISA added the bug to its KEV catalog on 2023-08-22 with known ransomware use, the Cuba ransomware group has been observed stealing credentials through this exploit, and EPSS assigns a 77.6% near-term exploitation probability (100th percentile).

Do: Apply the fixes Veeam provides in its security advisory immediately — per CISA's KEV listing, patch per vendor instructions or discontinue use — prioritizing internet-facing Cloud Connect servers. After patching, rotate all credentials stored in the configuration database, since they should be considered exposed, and review those accounts for signs of misuse. Restrict network access to the VBR service from untrusted networks and check servers for exploitation indicators such as unexpected connections to the service or anomalous logins with stored credentials.

7.578% KEV ransomware
  • Veeam Backup & Replication
largetens of thousands of deployments, of which thousands are internet-exposed (estimate)
CVE-2024-29212
Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its component

Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

NVD description · AI analysis pending
9.92%
  • veeam veeam service provider console
Full article358 words · extracted from helpnetsecurity.com · click to collapse

Veeam has patched a critical vulnerability (CVE-2024-29212) in Veeam Service Provider Console (VSPC) and is urging customers to implement the patch.

CVE-2024-29212

About CVE-2024-29212

Veeam Service Provider Console is a cloud platform used by managed services providers (MSPs) and enterprises to manage and monitor data backup operations.

“Service providers can deploy Veeam Service Provider Console to deliver Veeam-powered Backup-as-a-Service and Disaster Recovery-as-a-Service services to their customers. Enterprises can use the solution to streamline backup operations in remote and branch offices, or other locations,” the company explains.

CVE-2024-29212 exists due to an unsafe deserialization method used by the Veeam Service Provider Console server during communication between the management agent and its components. It affects VSPC versions 4.0, 5.0, 6.0, 7.0 and 8.0.

Exploiting the vulnerability – under certain conditions – may allow attackers to achieve remote code execution on the server machine on which VSPC has been installed. Attackers may thus be able to disrupt backup and disaster recovery processes – a boon to ransomware operators.

In 2023, cybercriminals exploited CVE-2023-27532, a vulnerability in Veeam Backup & Replication.

What to do?

The good news is that the vulnerability was discovered internally by Veeam and there is no mention of it being actively exploited.

“We encourage service providers using supported versions of Veeam Service Provider Console (versions 7 & 8) to update to the latest cumulative patch. Service providers using unsupported versions are strongly encouraged to upgrade to the latest version of Veeam Service Provider Console,” the company advised.

The vulnerability does not affect any other Veeam products.

Hunter.how, a search engine for internet researchers, detects over 1,600 internet-facing VSPC setups, mostly in the US.

UPDATE (May 28, 2024, 02:00 p.m. ET):

Veeam has issued an “enhanced update” to address CVE-2024-29212 and is urging admins to implement it.

“Although our initial patch, issued on May 7th, effectively addressed the primary concern, a subsequent review identified an area for further improvement. To ensure comprehensive protection, we swiftly developed and released a refined patch that fully mitigates the issue.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/05/08/cve-2024-29212/