First published: Thu Mar 17 2022(Updated: )
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam Backup \& Replication | >=10.0.0.4442<10.0.1.4854 | |
Veeam Backup \& Replication | >=11.0.0.825<11.0.1.1261 | |
Veeam Backup \& Replication | =10.0.1.4854 | |
Veeam Backup \& Replication | =10.0.1.4854-p20201202 | |
Veeam Backup \& Replication | =10.0.1.4854-p20210609 | |
Veeam Backup \& Replication | =11.0.1.1261 | |
Veeam Backup \& Replication | =11.0.1.1261-p20211123 | |
Veeam Backup \& Replication | =11.0.1.1261-p20211211 | |
Veeam Veeam Backup \& Replication | >=10.0.0.4442<10.0.1.4854 | |
Veeam Veeam Backup \& Replication | >=11.0.0.825<11.0.1.1261 | |
Veeam Veeam Backup \& Replication | =10.0.1.4854 | |
Veeam Veeam Backup \& Replication | =10.0.1.4854-p20201202 | |
Veeam Veeam Backup \& Replication | =10.0.1.4854-p20210609 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261-p20211123 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261-p20211211 | |
Veeam Backup & Replication | ||
>=10.0.0.4442<10.0.1.4854 | ||
>=11.0.0.825<11.0.1.1261 | ||
=10.0.1.4854 | ||
=10.0.1.4854-p20201202 | ||
=10.0.1.4854-p20210609 | ||
=11.0.1.1261 | ||
=11.0.1.1261-p20211123 | ||
=11.0.1.1261-p20211211 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26501 is a remote code execution vulnerability in Veeam Backup & Replication.
CVE-2022-26501 has a severity rating of 9.8 (Critical).
CVE-2022-26501 affects Veeam Backup & Replication versions between 10.0.0.4442 and 10.0.1.4854, and versions between 11.0.0.825 and 11.0.1.1261.
An attacker can exploit CVE-2022-26501 by accessing internal API functions of Veeam Distribution Service in the Backup & Replication application.
No, CVE-2022-26501 allows unauthenticated users to access the internal API functions.