First published: Fri Mar 10 2023(Updated: )
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam Backup \& Replication | =11.0.1.1261 | |
Veeam Backup \& Replication | =11.0.1.1261 | |
Veeam Backup \& Replication | =11.0.1.1261-p20211123 | |
Veeam Backup \& Replication | =11.0.1.1261-p20211211 | |
Veeam Backup \& Replication | =11.0.1.1261-p20220302 | |
Veeam Backup \& Replication | =12.0.0.1420 | |
Veeam Backup & Replication | ||
Veeam Veeam Backup \& Replication | =11.0.1.1261 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261-p20211123 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261-p20211211 | |
Veeam Veeam Backup \& Replication | =11.0.1.1261-p20220302 | |
Veeam Veeam Backup \& Replication | =12.0.0.1420 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27532 is a vulnerability in Veeam Backup & Replication Cloud Connect component that allows an unauthenticated user to obtain encrypted credentials stored in the configuration database.
The severity of CVE-2023-27532 is high with a CVSS score of 7.5.
CVE-2023-27532 affects Veeam Backup & Replication versions 11.0.1.1261, 11.0.1.1261-p20211123, 11.0.1.1261-p20211211, 11.0.1.1261-p20220302, and 12.0.0.1420.
No, CVE-2023-27532 does not require authentication for exploitation.
To mitigate the CVE-2023-27532 vulnerability, ensure you have applied the latest patch provided by Veeam and follow their recommended security best practices.