Proxmox VE

Proxmox VE 2

Proxmox VE 2

The Proxmox VE 2 reached end of service life on May 31, 2014 — Proxmox VE no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.

End of Service LifeEOSL Date: May 31, 2014
Issue Management

24/7 engineers own your Proxmox VE 2 incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
proxmox-ve
release
2
product Label
Proxmox VE
release Label
2
codename
lts
latest Version
2.3
release Date
2012-03-30
maintained
source Url
https://endoflife.date/proxmox-ve

Lifecycle Dates

End of Service Life
May 31, 2014
Last OEM Support
May 31, 2014

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Proxmox VE 2 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Proxmox VE 2?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Proxmox VE 2 when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Proxmox VE 2 Support: Frequently Asked Questions

Is the Proxmox VE 2 still supported?

Proxmox VE ended support for the Proxmox VE 2 on May 31, 2014 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.

When is the Proxmox VE 2 end of service life (EOSL) date?

Proxmox VE lists the end of service life for the Proxmox VE 2 as May 31, 2014.

Can I keep using the Proxmox VE 2 after its EOSL date?

Yes. EOSL means Proxmox VE stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Proxmox VE 2 cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Proxmox VE 2

4 published CVEs affect the Proxmox VE 2, including 3 rated critical or high severity. Proxmox VE no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.

CVESeverityCVSSPublishedSummary
CVE-2022-35508CRITICAL9.8Dec 4, 2022Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions an
CVE-2022-31358CRITICAL9.0Dec 14, 2022A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.
CVE-2022-35507HIGH7.1Dec 4, 2022A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow injection of response headers with %0d. This is fixed in pve-http-server 4.1-3.
CVE-2014-4156MEDIUM5.3Jan 27, 2020Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
Get Third Party Support

Related Proxmox VE Products

All Proxmox VE products →
Proxmox VE 2
Save 40-70% vs OEM
Get Third Party Support