This article documents a vulnerability discovered in a core service of Veeam Backup & Replication and Veeam Cloud Connect.
This vulnerability does not affect other Veeam products (e.g., Veeam Backup for Microsoft 365, Veeam Agent for Microsoft Windows, Veeam ONE, Veeam Service Provider Console, etc.).
Vulnerability CVE-2023-27532 in a Veeam Backup & Replication component allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.
Severity: High
CVSS v3 score: 7.5
Notes:
This vulnerability was reported by Shanigen.
Correction: This article initially listed the vulnerability ID as CVE-2023-27530, the correct vulnerability ID is CVE-2023-27532.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case