EXPOSURES › CVE-2023-27532
CVE-2023-27532
CRITICAL ⌖ ON CISA KEV · EXPLOITEDVeeam Backup & Replication Cloud Connect allowed unauthenticated attackers to steal encrypted credentials from its configuration database, enabling access to backup infrastructure hosts.
Veeam's Cloud Connect component lacked authentication for a critical function, letting unauthenticated users within the network perimeter extract encrypted credentials. This exposes backup infrastructure hosts to compromise, directly impacting DIB compliance by failing to protect critical data repositories and violating access control requirements. Organizations must verify that backup infrastructure components enforce strict authentication and monitor for credential theft.
Shame score — A missing authentication flaw in a critical function allowed unauthenticated attackers to steal credentials, leading to ransomware-linked exploitation and demonstrating severe negligence in securing backup infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.