Skip to content
COOEY

EXPOSURES › CVE-2023-27532

CVE-2023-27532

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-08-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-27532 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatched

Veeam Backup & Replication Cloud Connect allowed unauthenticated attackers to steal encrypted credentials from its configuration database, enabling access to backup infrastructure hosts.

Veeam's Cloud Connect component lacked authentication for a critical function, letting unauthenticated users within the network perimeter extract encrypted credentials. This exposes backup infrastructure hosts to compromise, directly impacting DIB compliance by failing to protect critical data repositories and violating access control requirements. Organizations must verify that backup infrastructure components enforce strict authentication and monitor for credential theft.

Shame score — A missing authentication flaw in a critical function allowed unauthenticated attackers to steal credentials, leading to ransomware-linked exploitation and demonstrating severe negligence in securing backup infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.