Proxmox VE 7 is vulnerable to some type of 0day/RCE non auth

Obviously 7 is EOL, but the big main issue here is, why is something like this not firewalled off with restricted IP access. Also have you done any backups at all in those 4 years?

Even my oldest bodged MBR GRUB install, has been updated over time and behind IP ACL.

Never sit relying on vendor to keep things secure for you (which is why people have given tough love in the replies), assume it can be compromised, assume your server might go on fire one day, take precautions against these events.
 
Last edited:
  • Like
Reactions: Johannes S
Would Proxmox be taken more seriously when it would take away the user's ability to control and customize it (based on GNU/Linux and OSS)? More like an enterprise appliance where you are used to pay a service technician to update it regularly? At least your setup would be "in the hands of professionals". I'm using hyperbole and satire here but maybe it would match better with the expectations created by other hypervisors? Regardless of my weird ideas, what would help people to stay up to date?
Sadly and most likely compilance theater. If they are in an environment where it's mandatory to have a cyber security insurance and said insurance state in their conditions that they only pay if you patched all of your systems then change managers might finally approve of doing patches. Even then they also might pass the ball to the legal department wheter the "patch or we don't pay"-clause might be taken to court.
Another potential way to enforce this via compilance theater/checkboxing would be a legal obligation like the moronic "you are not allowed to update without recertifying everything for a high amount of cash"-rules in parts of critical infrastructure. It was quite funny to read following report on an talk kernel developer Greg Kroah-Hartmann did on Linux kernels cve issueing process:

One participant in the panel discussion, however, mentioned that the many CVEs are a huge problem in areas where updates are difficult and expensive due to certification regulations –, for example when using Linux in hospitals. Kroah-Hartman explained that US and EU legislators have recognized the problem and are working on solutions, but that this will take time.
https://www.heise.de/en/news/Linux-...s-of-the-CVE-flood-in-the-kernel-9963850.html

So if the same rules state that any updates needs an recertification would also state that any CVE or security issue with a known fix needs to be fixed asap otherwise you loose your clearance for such environments, more people will update.

To be clear: I hate the CVE process and compilance-instead-actual-security debacle of "enterprise it" with passion, but if managment only cares about ticking checkboxes, then that would help. I wouldn't hold my breath though, that lawmakers or insurance companies will actually do this.