TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2023-27532

HIGHCISA KEV
7.5

Beschreibung

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

CVE Details

CVSS v3.1 Bewertung7.5
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/10/2023
Zuletzt geandert11/3/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerVeeam
ProduktBackup & Replication
SchwachstellennameVeeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
KEV Aufnahmedatum2023-08-22
Behebungsfrist2023-09-12
Ransomware-NutzungKnown

Betroffene Produkte

veeam:veeam_backup_\&_replication

Schwachen (CWE)

CWE-306CWE-306

Referenzen

https://www.veeam.com/kb4424(support@hackerone.com)
https://www.veeam.com/kb4424(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.