Vulnerabilidad crítica en la copia de seguridad de Veeam

Veeam, a leading provider of backup solutions, has reported a critical vulnerability affecting several of its cloud backup products. Although the vulnerability has been addressed in most of these products through previous updates, a recent update has been released specifically for Veeam Backup for Salesforce, which is also impacted. The vulnerability could potentially allow attackers to execute malicious code through a man-in-the-middle attack. The National Institute of Standards and Technology (NIST) has yet to classify this vulnerability, although Veeam has rated its severity at CVSS 3.1 as a score of 9.0.

The affected Veeam products include:

– Veeam Backup for Salesforce versions 3.1 and later
– Veeam Backup for Nutanix AHV versions 5.0 and 5.1
– Veeam Backup for AWS versions 6A and 7
– Veeam Backup for Microsoft Azure versions 5A and 6
– Veeam Backup for Google Cloud versions 4 and 5
– Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization for versions 3, 4.0, and 4.1

For all products, excluding Veeam Backup for Salesforce, updates to address the vulnerability were made available between July and December 2024. Users of Veeam Backup & Replication 12.3 who have previously updated their software should not be affected by this vulnerability.

In light of this critical security issue, CERT-SE has urged customers to promptly apply the manufacturers’ updates to mitigate the risk. Keeping software up-to-date is a fundamental practice to ensure the security of systems and data, especially in the context of modern threats that exploit vulnerabilities.

In summary, Veeam has identified a critical vulnerability in several of its backup solutions, warning of the potential for serious security risks if left unaddressed. It is vital for users to take immediate action by applying updates to safeguard their systems against potential attacks.

Enlace de la fuente, haz clic para tener más información

Artículos y alertas de seguridad

Consultar más contenidos y alertas

Alertas y noticias de seguridad de la información

Contacta

Contacta con nosotros para obtener soluciones integrales en IT y seguridad de la información

Estamos encantados de responder cualquier pregunta que puedas tener, y ayudarte a determinar cuáles de nuestros servicios se adaptan mejor a tus necesidades.

Nuestros beneficios:
¿Qué sucede a continuación?
1

Programamos una llamada según tu conveniencia.

2

Realizamos una reunión de descubrimiento y consultoría.

3

Preparamos una propuesta.

Agenda una consulta gratuita