CVE-2023-27532

Confirmed PUBLISHED

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This...

Veeam · Veeam Backup & Replication
Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High

At a Glance

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

ransomware cisa nessus_scanner malware
CVE Published
Mar 10, 2023
Exploitation Reported
Aug 22, 2023
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
Veeam Backup & Replication

Fixed Versions: v12 (build 12.0.0.1420 P20230223)

Affected
n/a
Veeam Backup & Replication

11a (build 11.0.1.1261 P20230227)

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.