Hi All,
Would it be possible to replace or update the OpenSSL component only on the Veeam Agent for Windows [v13.0.3.1220] due to the Critical bug below, or is it better to wait until Veeam released the latest update ?
Recommended Action: Download and install patches as instructed
Description:A heap buffer overflow from converting large OCTET STRINGs to hex on 32 bit OpenSSL may crash or allow code execution; caused by 32 bit multiplication overflow; affects non FIPS OpenSSL 3.x on 32 bit systems.
Affected Products:OpenSSL
CVE IDs:CVE-2026-31789
Vendor Information:https://www.openssl.org/news/vulnerabilities.html
Vendor Patch Download:https://wiki.openssl.org/index.php/Binaries
Thank you,
