CVE-2023-27532

unknown KEV
Published 2023-08-22 · Modified 2023-08-22
CVSS v3
CVSS v2
VIR risk
1.5

Description

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

CISA KEV

Vendor
Veeam
Product
Backup & Replication
Due date
2023-09-12

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://www.veeam.com/kb4424; https://nvd.nist.gov/vuln/detail/CVE-2023-27532

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.