Skip to main content

Veeam Service Provider Console Vulnerability - CVE-2024-29212


coolsport00
Forum|alt.badge.img+20

Hello all -

Veeam just releasd a KB on a recent VSPC vulnerability. You can read more about it, and remediation steps in the below KB:

https://www.veeam.com/kb4575

4 comments

Mildur
Forum|alt.badge.img+12
  • Influencer
  • 1035 comments
  • May 28, 2024

 

It‘s the same KB and CVE from May 7th. It was just updated today.

 

 

 

Best,

Fabian


coolsport00
Forum|alt.badge.img+20
  • Author
  • Veeam Legend
  • 4139 comments
  • May 28, 2024
Mildur wrote:

 

It‘s the same KB and CVE from May 7th. It was just updated today.

 

 

 

Best,

Fabian

Thanks Fabian.


Mildur
Forum|alt.badge.img+12
  • Influencer
  • 1035 comments
  • May 28, 2024

The reason for the KB update was a repack of the previous patch:

https://www.veeam.com/kb4509

 

8.0.0.19552

This is a repack of build 8.0.0.19236 that includes an enhanced update to address the critical vulnerability in VCSP. Although our initial patch effectively addressed the primary concern, a subsequent review identified an area for further improvement. To ensure comprehensive protection, we have swiftly developed and released a refined patch that fully mitigates the issue. We're confident this updated version reinforces the security of VCSP and demonstrates our commitment to continually strengthening our response measures.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8492 comments
  • May 28, 2024

Thanks for this. Will get it looked at and installed.


Comment