last updated April 29, 2024 by Steve P.

Resolving CVE-2023-48795 on VRA’s

  • Our security team does vulnerability scanning. Every VRA in our environment is reporting this Linux SSH vulnerability called Terrapin. What are the plans for resolving this issue. I cannot find any Zerto documentation on it.

    10.U3 has the fix .. but here’s the gotcha, unless you are installing new, 10.0 U3 you can’t get to because of a bug, because the migration path is from 9.7  to 10.0U2P1 ( migration tool ) and there is no good way to get to 10.0U3 to fix it … now you have to wait until next month to go to 10.0U4.   Zerto really messed up on this one…

