The fix for the vulnerability discussed in this article has been automatically deployed to all Veeam Backup for Google Cloud Backup Appliances that have been configured to have access to repository.veeam.com. Most users will have no additional actions to perform beyond confirming the Veeam Updater component version.
For deployments where the Veeam Backup for Google Cloud Backup Appliance does not have network access to the Veeam Update Repository, the fix must be deployed manually.
During internal testing, a vulnerability was discovered within the Backup Appliance component of Veeam Backup for Google Cloud that allows users to bypass authentication mechanisms.
Severity: Critical
CVSS v3 Score: 10.0
Status: Resolved
1 The Veeam Updater checks for updates every 24 hours. The Veeam Updater will automatically install updates to the Veeam Updater component and critical updates for other components.
2 The update check requires that the Veeam Backup for Google Cloud backup appliance have internet access and be able to reach repository.veeam.com as documented in the product user guide. If the Veeam Backup for Google Cloud backup appliance does not have internet access, a manual update process is available. Please contact Veeam Support for assistance. After manual updating, the Updater UI will have to be reopened to see the updated version listed.
3 If the Veeam Updater UI is opened before it has updated automatically, clicking "Check for Updates..." will cause the Veeam Updater UI to download the update and become inaccessible while the Backup Appliance is automatically restarted to apply the fix. After reopening the Veeam Updater, the new version number will be displayed.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case