216.73.216.233

CVE-2023-27532

· Published 22/08/2023 02:00 · Modified 27/05/2026 21:40 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2023-27532

Essential information

Published
22/08/2023 02:00
Modified
27/05/2026 21:40
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
7.5 HIGH (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:N/A:N

CVSS metrics

Description

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

NVD status

NVD
View on NVD