Veeam has released a security patch to fix a vulnerability that affects all Veeam Backup & Replication versions.
The addressed vulnerability could allow the remote attacker to obtain encrypted credentials stored in the configuration database and gain access to the backup infrastructure hosts.
It should be highlighted that the patch must be installed on the Veeam Backup & Replication server using the ISO images dated 20230223 (V12) and 20230227 (V11) or later.
Veeam Backup and Replication Information Disclosure (CVE-2023-27532):
• CVSS: 7.5
• Attack Vector: Network
• Attack Complexity: Low
• Privileges Required: None
• User Interaction: None
• Consequences: Obtain Information
The enterprise should deploy this patch as soon as the testing phase is completed.
Veeam Security Update
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |