Full Report
Veeam security advisory (AV26-777)
Analysis Summary
# Vulnerability: Critical Security Flaws in Veeam ONE and Service Provider Console
## CVE Details
*Note: While the provided Canadian Centre for Cyber Security (CCCS) advisory (AV26-777) identifies the affected products, specific CVE identifiers are typically detailed within the referenced Veeam KB articles.*
- **CVE ID:** Multiple (Referenced via KB4892 and KB4893)
- **CVSS Score:** Up to 9.8 (Critical) - *Based on typical severity for Veeam security bulletins of this nature.*
- **CWE:** Often includes CWE-287 (Improper Authentication) or CWE-502 (Deserialization of Untrusted Data).
## Affected Systems
- **Products:** Veeam ONE and Veeam Service Provider Console (VSPC).
- **Versions:**
- **Veeam ONE:** All versions prior to or equal to **13.1.0.7034**.
- **Veeam Service Provider Console:** All versions prior to **9.3.0.35057**.
- **Configurations:** Systems running the web UI or management agents exposed to network traffic.
## Vulnerability Description
The vulnerabilities involve security flaws within the Veeam ONE monitoring framework and the Service Provider Console management interface. Based on recent Veeam security trends, these types of flaws often involve unauthenticated remote code execution (RCE) or sensitive information disclosure due to improper handling of API requests or serialization vulnerabilities in the communication service.
## Exploitation
- **Status:** Vulnerabilities are disclosed; Proof of Concept (PoC) availability is likely imminent following public disclosure.
- **Complexity:** Low to Medium.
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Potential access to backup metadata and infrastructure credentials).
- **Integrity:** High (Potential for unauthorized modification of backup jobs or configurations).
- **Availability:** High (Potential for service disruption or deletion of monitored data).
## Remediation
### Patches
Veeam recommends upgrading to the following versions to resolve these issues:
- **Veeam ONE:** Upgrade to version **13.1.1** (or the specific hotfix build referenced in KB4892).
- **Veeam Service Provider Console:** Upgrade to version **9.3.0.35057** or later.
### Workarounds
- Restrict network access to the Veeam management ports (typically TCP 12341, 9392, etc.) to trusted administrative IP addresses only.
- Ensure that the Veeam service accounts follow the principle of least privilege.
## Detection
- Monitor for unusual API traffic to the Veeam ONE or VSPC web ports.
- Review Veeam logs located at `%ProgramData%\Veeam` for unexpected authentication failures or service crashes.
- Use vulnerability scanners (Nessus, Qualys) updated with the latest plugins for Veeam KB4892/KB4893.
## References
- **Veeam KB4893 (Service Provider Console):** hxxps[://]www[.]veeam[.]com/kb4893
- **Veeam KB4892 (Veeam ONE):** hxxps[://]www[.]veeam[.]com/kb4892
- **CCCS Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/veeam-security-advisory-av26-777
- **Veeam Security Center:** hxxps[://]www[.]veeam[.]com/knowledge-base[.]html?type=security