CVE-2023-27532
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 September 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 77.61% probability · 100th percentile
- CISA KEV
- Listed 22 August 2023 · due 12 September 2023 · used in ransomware campaigns
- Weakness
- CWE-306
- Affected
- veeam/veeam backup \& replication
- Source
- support@hackerone.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.veeam.com/kb4424; https://nvd.nist.gov/vuln/detail/CVE-2023-27532
References
- https://www.veeam.com/kb4424Vendor Advisory
- https://www.veeam.com/kb4424Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27532US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.