ConnectWise Vulnerability Potentially Exposes Thousands of Servers to Attack

The flaw impacts the ConnectWise Recover backup and disaster recovery product.

Claudia Adrien

October 31, 2022

2 Min Read
Vulnerability, 3 vulnerabilities
Shutterstock

ConnectWise has unveiled updates that patch a critical vulnerability which could potentially expose thousands of servers to cyberattacks. The flaw impacts the ConnectWise Recover backup and disaster recovery product. It impacted the R1Soft server backup manager as well.

Cybersecurity experts called into question whether announcing both the vulnerability and the patch last Friday was a good idea. Many affected servers would likely remain unpatched over the weekend, leaving them exposed to attacks. (ConnectWise Recover users should update to version 2.9.9. R1Soft users should update to version 6.16.4.)

Hanslovan-Kyle_Huntress.jpgHuntress CEO Kyle Hanslovan said researchers at his company discovered the vulnerability.

View post on X

According to reporting from Security Week, Hanslovan said Huntress experts demonstrated how they could push ransomware to nearly 5,000 internet-exposed R1Soft servers. Many of these are in North America and Europe.

“There’s also a possible supply chain impact considering that many of the affected systems belong to cloud hosting providers and MSPs,” Eduard Kovacs wrote.

View post on X

ConnectWise has been exploited in previous attacks, including last year by Noberus, part of the ransomware family.

Patrick Beggs is CISO of ConnectWise.

“We have informed our [customers] of the fix and encouraged those with on-premises instances of the impacted product to install the patch as soon as possible,” Beggs told Dark Reading. (Dark Reading shares a parent company with Channel Futures.)

Most organizations using ConnectWise Recover don’t need to take further action to protect against the vulnerability; however, if “R1Soft is self-managed, we encourage these [customers] to apply the patch quickly,” the company said.

Want to contact the author directly about this story? Have ideas for a follow-up article? Email Claudia Adrien or connect with her on LinkedIn.

Read more about:

MSPs

About the Author

Claudia Adrien

Claudia Adrien is a reporter for Channel Futures where she covers breaking news. Prior to Informa, she wrote about biosecurity and infectious disease for a national publication. She holds a degree in journalism from the University of Florida and resides in Tampa.

Free Newsletters for the Channel
Register for Your Free Newsletter Now

You May Also Like