PSA & RMM

Solve any challenge with one platform

Operate more efficiently, reduce complexity, improve EBITDA, and much more with the purpose-built platform for MSPs.

Cybersecurity & Data Protection

Ensure security and business continuity, 24/7

Protect and defend what matters most to your clients and stakeholders with ConnectWise's best-in-class cybersecurity and BCDR solutions.

Hyperautomation

Integrate and automate to unlock cost savings

Leverage generative AI and RPA workflows to simplify and streamline the most time-consuming parts of IT.

University

University Log-In

Check out our online learning platform, designed to help IT service providers get the most out of ConnectWise products and services.

Resources

Explore the ConnectWise Resource Center

Search our resource center for the latest MSP ebooks, white papers, infographics, webinars and more!

About Us

Experience the ConnectWise Way

Join hundreds of thousands of IT professionals benefiting from and contributing to a legacy of industry leadership when you become a part of the ConnectWise community.

News & Press

Experience the ConnectWise Way

Join hundreds of thousands of IT professionals benefiting from and contributing to a legacy of industry leadership when you become a part of the ConnectWise community.

ConnectWise

ConnectWise BCDR and R1Soft Server Backup Manager Critical Security Release

10/28/2022

Products: Recover
Severity: Critical
Priority: 1 - High

Vulnerability 

CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component.

Severity 

Critical – Vulnerabilities that could allow the ability to execute remote code or directly access confidential data.

Priority  

1 – Vulnerabilities that are either being targeted or have a higher risk of being targeted by exploits in the wild. Recommend patching as soon as possible.  

Affected versions 

ConnectWise Recover: Recover v2.9.7 and earlier versions are impacted.

R1Soft: SBM v6.16.3 and earlier versions are impacted.

Remediation 

ConnectWise Recover:

Affected ConnectWise Recover SBMs have automatically been updated to the latest version of Recover (v2.9.9).

R1Soft:

Upgrade the server backup manager to SBM v6.16.4 released October 28, 2022 using the R1Soft upgrade wiki.

Please refer to the release notes for more information. 

Additional information 

Visit home.connectwise.com/securityBulletin/635bd34f6e80800001cdcfbe