HIGH

CVE-2023-27532

Veeam Veeam Backup \& Replication 2023-03-10 CVSS v3.1
CVSS
7.5
KEV

Description

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

Summary dbcve.org

Veeam Backup & Replication contains a vulnerability that allows attackers to obtain encrypted credentials stored in the configuration database. By accessing these credentials, an attacker could decrypt them and gain unauthorized access to backup infrastructure hosts.

Mitigation

Apply the vendor patch for CVE-2023-27532 and rotate all credentials that may have been stored in the affected Veeam configuration database.

Weakness (CWE)

CWE-306 Missing Authentication

EPSS Score

77.61%
Probability of exploitation in next 30 days
99.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE