Junglewise Threat Intelligence

CVE-2023-27532: Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

CVE-2023-27532 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-08-22

Technologies: Nakivo Backup, Nakivo Replication, Veeam Backup & Replication. Vendors: Nakivo, Veeam.

Executive brief

The Veeam Backup & Replication Cloud Connect component contains a missing authentication vulnerability. An unauthenticated attacker within the backup infrastructure network perimeter can obtain encrypted credentials from the configuration database, potentially gaining full access to backup infrastructure hosts.

Affected products

  • Veeam Veeam Backup & Replication 11.0.1.1261, 12.0.0.1420

Timeline

  • 2023-03-10: disclosed: NVD Published Date
  • 2023-08-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-08-22: exploited: Reported as exploited in the wild

Related threats