Proxmox VE 1
Proxmox VE 1
The Proxmox VE 1 reached end of service life on Jan 31, 2013 — Proxmox VE no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Proxmox VE 1 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- proxmox-ve
- release
- 1
- product Label
- Proxmox VE
- release Label
- 1
- codename
- lts
- latest Version
- 1.9
- release Date
- 2011-09-13
- maintained
- source Url
- https://endoflife.date/proxmox-ve
Lifecycle Dates
- End of Service Life
- Jan 31, 2013
- Last OEM Support
- Jan 31, 2013
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Proxmox VE 1 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Proxmox VE 1?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Proxmox VE 1 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Proxmox VE 1 Support: Frequently Asked Questions
Is the Proxmox VE 1 still supported?
Proxmox VE ended support for the Proxmox VE 1 on Jan 31, 2013 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Proxmox VE 1 end of service life (EOSL) date?
Proxmox VE lists the end of service life for the Proxmox VE 1 as Jan 31, 2013.
Can I keep using the Proxmox VE 1 after its EOSL date?
Yes. EOSL means Proxmox VE stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Proxmox VE 1 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Proxmox VE 1
4 published CVEs affect the Proxmox VE 1, including 3 rated critical or high severity. Proxmox VE no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-35508 | CRITICAL | 9.8 | Dec 4, 2022 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions an |
| CVE-2022-31358 | CRITICAL | 9.0 | Dec 14, 2022 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/. |
| CVE-2022-35507 | HIGH | 7.1 | Dec 4, 2022 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3. |
| CVE-2014-4156 | MEDIUM | 5.3 | Jan 27, 2020 | Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability |