Veeam Security Update 09 March 2023

Veeam has released a security patch to fix a vulnerability that affects all Veeam Backup & Replication versions.

The addressed vulnerability could allow the remote attacker to obtain encrypted credentials stored in the configuration database and gain access to the backup infrastructure hosts.

It should be highlighted that the patch must be installed on the Veeam Backup & Replication server using the ISO images dated 20230223 (V12) and 20230227 (V11) or later.

Veeam Backup and Replication Information Disclosure (CVE-2023-27532):

• CVSS: 7.5

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: None

• Consequences: Obtain Information

Vulnerabilities
  • CVE-2023-27532
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.
Veeam Security Update

References