Veeam has identified a Man in the Middle vulnerability in its Veeam Updater that affects the following current product:
- Veeam Backup for Salesforce: 3.1 or older
Also affected are older versions of other products:
- Veeam Backup for Nutanix AHV: 5.0 or 5.1
- Veeam Backup for AWS: 6a or 7
- Veeam Backup for Microsoft Azure: 5a or 6
- Veeam Backup for Google Cloud: 4 or 5
- Veeam Backup for Oracle Linux Virtualisation Manager and Red Hat Virtualization: 3, 4.0 or 4.1
Affected versions should be updated as soon as possible
You can check whether you are affected by displaying your current version:
- On your appliance, go to the Configuration page (top right) Select Support Information → Updates
- Click Check and View Updates
- Switch to the History tab
You can carry out the update via the autoupdater.
This of course raises the question that you are making yourself vulnerable at this very moment.
This is true. However, you can decide for yourself whether the risk of an attack on the transfer path between the Auto-Updater and Veeam is more likely or on the path you have to choose for a manual installation.
Note: Manual installation involves more (vulnerable) components.
How to avoid Man in the Middle vulnerabilities in auto-updaters
Man in the Middle security vulnerabilities in auto-updaters are avoided by checking whether the remote station - which delivers patches - is legitimised. If the manufacturer uses certificate pinning, such errors can be avoided. If the manufacturer uses certificate pinning, it specifies that the auto-updater may only accept certain pre-defined certificates.
If you have any questions about Veeam, please send me an e-mail.
Matthias Mrugalla, Head of Managed Solutions
Phone +49 174 310 81 84