Skip to main content
Question

Vulnerability CVE-2023-38546


Dear Team, 

 

We have two Vulnerability ( VE-2023-38545 and VE-2023-38546), VE-2023-38546 see it post. 

Could kindly help to fix VE-2023-38546? What should we need to do to fix it ? 

How to resolve this issue ? 

Thank you.

Best regards,

RAING Sopheaktra

6 comments

CarySun
Forum|alt.badge.img+7
  • Veeam Vanguard
  • 200 comments
  • December 18, 2023

Veeam Backup & Replication is not vulnerable to CVE-2023-38545 because it does not use SOCKS5 protocol. 
veeam.com/kb4523

https://forums.veeam.com/veeam-agents-for-linux-mac-aix-solaris-f41/veeam-agent-for-linux-cve-2023-38545-cve-2023-38546-t91367.html

 


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • December 18, 2023

To add, you can remote the affected binaries as per the KB which should stop it being flagged by your Vulnerability Scanner with no detrimental effect on your installation. 


randyweis
Forum|alt.badge.img+4
  • Experienced User
  • 55 comments
  • December 18, 2023

The main problem with ignoring it (because Veeam doesn’t use SOCK5) is that scanners will continue to flag the vulnerability every time they scan, and that just doesn’t sit well security teams. I’m not sure what dips means when he says to “remote” the affected binaries”. Here is the KB article released last week about this:

https://www.veeam.com/kb4523

 


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • December 18, 2023

That was a typo. It should have said remove*


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8512 comments
  • December 18, 2023

I would just remove the binaries associated in the KB posted to stop the scanner flagging things.  Easiest solution to me.


randyweis
Forum|alt.badge.img+4
  • Experienced User
  • 55 comments
  • December 18, 2023

But there are two impornant notes in the KB.

VDDK Library Must Remain on VMware Backup Proxies

Do not remove the VDDK libraries from VMware Backup Proxies. Removing the VDDK libraries from a VMware Backup Proxy will cause operations that attempt to use that proxy to communicate with VMware vSphere to fail with the error documented in KB2678.

Veeam Transport Redeployment

If the Veeam Transport package is reinstalled, either manually or as a result of an upgrade, the VDDK libraries will be reinstalled and will have to be removed again.


Comment