CVE-2023-27532
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.
CISA KEV
- Vendor
- Veeam
- Product
- Backup & Replication
- Due date
- 2023-09-12
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://www.veeam.com/kb4424; https://nvd.nist.gov/vuln/detail/CVE-2023-27532
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.