HIGH
CVE-2023-27532
CVSS
7.5
KEV
Description
Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
Summary dbcve.org
Veeam Backup & Replication contains a vulnerability that allows attackers to obtain encrypted credentials stored in the configuration database. By accessing these credentials, an attacker could decrypt them and gain unauthorized access to backup infrastructure hosts.
Mitigation
Apply the vendor patch for CVE-2023-27532 and rotate all credentials that may have been stored in the affected Veeam configuration database.
Weakness (CWE)
CWE-306
Missing Authentication
EPSS Score
77.61%
Probability of exploitation in next 30 days
99.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.