CVE-2023-27532 is a critical vulnerability in Veeam Backup & Replication that allows attackers to obtain encrypted credentials from the configuration database, potentially leading to unauthorized access to backup infrastructure hosts. With a CVSS score of 7.5 (High) and an EPSS score indicating high exploitability, this network-exploitable flaw requires no user interaction and has a severe impact on confidentiality. This vulnerability is actively exploited in the wild, notably by ransomware groups like Akira and Fog, as confirmed by its inclusion in the KEV catalog and extensive media coverage. While no public Metasploit or ExploitDB modules exist, community discussions and a recent blog post detail methods for achieving code execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.0.1.1261CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:* | ||
11.0.1.1261CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:-:*:*:*:*:*:* | ||
11.0.1.1261CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20211123:*:*:*:*:*:* | ||
11.0.1.1261CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20211211:*:*:*:*:*:* | ||
11.0.1.1261CPE matchmatch criteria | cpe:2.3:a:veeam:veeam_backup_\&_replication:11.0.1.1261:p20220302:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.