Executive brief
The Veeam Backup & Replication Cloud Connect component contains a missing authentication vulnerability. An unauthenticated attacker within the backup infrastructure network perimeter can obtain encrypted credentials from the configuration database, potentially gaining full access to backup infrastructure hosts.
Affected products
- Veeam Veeam Backup & Replication 11.0.1.1261, 12.0.0.1420
Timeline
- 2023-03-10: disclosed: NVD Published Date
- 2023-08-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-08-22: exploited: Reported as exploited in the wild