Third Party Index

Snapshot 20863

Document
Subprocessor list
URL
https://trust.pax8.com/?itemUid=e3fae2ca-94a9-416b-b577-5c90e382df57
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
373428 bytes
SHA-256 (raw)
962f725c2e6e4060fdfa43587d9716c98aa40c8fb4f1be1399cad490185ae8e8
SHA-256 (normalized text)
e04c40b1048b9ec831dd3836ac37110e149af92d18344b423694d32847f12824

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Trust Center
Start your security review
View & download sensitive information
Ask for information
Overview
Welcome to Pax8's Trust Center. We earn your trust by doing what we say we'll do and by being transparent with our customers and stakeholders, which is why we've provided our security, compliance, and privacy information in one, easy-to-access site.
Trust thrives in situations where everyone can win together. This is especially important for managed service providers (MSPs), because they are entrusted to protect the critical IT infrastructure and data of their clients. We recognize that our customers can only deliver on their promises when Pax8 operates as a trustworthy partner.
Pax8's security and privacy programs are led by industry veterans with decades of experience:
Robb Reck: Chief Trust & Security Officer
Carrie Schiff: Chief Legal Officer
Compliance
Cyber Essentials
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Documents
DOCUMENTSPax8's Approach to GDAP
DOCUMENTSPax8 Trusted IPs
DOCUMENTSSentinelOne SOC2 report
REPORTSPentest Report
REPORTSUK ICO Data Protection Registration Certificate
COMPLIANCECyber Essentials
COMPLIANCEISO/IEC 27001
COMPLIANCEPCI DSS
COMPLIANCESOC 2 Type 2
LEGALCyber Insurance
AIAI Compliance Summary
AIAI Vision
Risk Profile
Data Access LevelInternal
Impact LevelModerate
Critical DependenceNo
View more
Product Security
Audit Logging
Data Security
Integrations
View more
Reports
HIPAA Report
PCI DSS
Pentest Report
View more
Data Security
Data Backups
Encryption-at-rest
Encryption-in-transit
View more
AI
AI Vision
AI Compliance Summary
Ethics & Compliance
Anti-Modern Slavery
Code of Business Conduct and Ethics
Legal
Subprocessors
Cyber Insurance
Data Processing Agreement
Data Privacy
Commitment to Accountability
Data Protection Principles
Privacy Notice
View more
Infrastructure
Status Monitoring
Cloud Workload Protection
Corporate Security
Employee Training
HR Security
Internal Assessments
View more
Subprocessors
Trust Center Updates
Pax8 Security Advisory: Veeam Backup and Replication (VBR) Vulnerability (CVE-2024-40711)
Vulnerabilities
This Pax8 Security Alert is a notification of a potential security threat for partners who are using Veeam Backup and Replication.
A critical vulnerability with Veeam Backup and Replication requires immediate attention. The exploitation of this Remote Code Execution Vulnerability has been reported and poses a significant threat. The vulnerability was made public in September 2024 and a product version has been released to address this vulnerability. Users of Veeam Backup products are recommended to take action to patch before exploitation occurs.
About this Vulnerability
The vulnerability could potentially allow remote code execution on systems with version 12.1.2 Veeam Backup and Replication, leading to full system compromise.
The technical information related to how this vulnerability has been exploited was noted as, "Each time, the attackers exploited VEEAM on the URI /trigger on port 8000, triggering the Veeam.Backup.MountService.exe to spawn net.exe. The exploit creates a local account, 'point,' adding it to the local Administrators and Remote Desktop Users groups."
Potential Impact
Systems operating on version 12.1.2 are at risk. Attackers could exploit this vulnerability to move laterally within infrastructure, deploy ransomware, or other malicious software.
Recommend Immediate Patching Actions
Pax8 Security team advises patching per the Veeam recommendation for version 12.1.2 of Veeam Backup and Replication and update with version 12.2.
References
Veeam Security Bulletin (September 2024)
Critical Veeam Vulnerability Exploited (The Hacker News)
Pax8 Security Advisory: OpenSSH Vulnerability (regreSSHion CVE-2024-6387)
Vulnerabilities
This Pax8 Security Advisory is a notification of a potential security threat.
A critical OpenSSH vulnerability requires immediate attention. Remote Code Execution Vulnerabilities are rare but pose a significant threat. The vulnerability has been validated in a lab environment by Qualys and was made public on 1 July 2024. Use this brief window to patch before exploitation begins.
About this Vulnerability
The vulnerability could potentially allow remote code execution on systems accessible over SSH (port 22) as the 'root' user, leading to full system compromise.
Potential Impact
Systems with exposed port 22 are at risk. Attackers could exploit this vulnerability to move laterally within infrastructure, deploy ransomware, or other malicious software.
Recommend Immediate Patching Actions
Pax8 Security team advises patching the following versions of OpenSSH:
OpenSSH versions before 4.4p1
OpenSSH versions 8.5p1through but not including 9.8p1
References
Qualys Community Blog regreSSHion
CSO Online Article OpenSSH Vulnerability
Qualys Securiy Advisory Technical Details