← Back to browse · API

CVE-2023-27532

Severity
HIGH
CVSS
7.5
EPSS
0.7761
Risk score
82.16
CISA KEV
Yes
PoC
No
Published
2023-08-22
Modified
2023-08-22
First seen
2026-08-07
Aliases
EUVD-2023-31287, GHSA-HH3C-XPMG-W5FR
Products
Veeam:Backup & Replication, n/a:Veeam Backup & Replication 11a (build 11.0.1.1261 P20230227), n/a:Veeam Backup & Replication Fixed Versions: v12 (build 12.0.0.1420 P20230223)
Sources
euvd EUVD-2023-31287
cisa.gov CVE-2023-27532

Description

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

References