跳转到帖子

Veeam Backup and Replication: Missing Authentication for Critical Function (CVE-2023-27532)

recommended_posts

发布于
  • Members

Veeam Backup and Replication: Missing Authentication for Critical Function (CVE-2023-27532)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
03/07/2023
Created
03/28/2023
Added
03/24/2023
Modified
01/27/2025

Description

The vulnerable process, Veeam.Backup.Service.exeDefault path:C:\Program Files\Veeam\Backup and Replication\Backup\Veeam.Backup.Service.exe (TCP 9401 by default), allows an unauthenticated user to request encrypted credentials.

Solution(s)

  • veeam-backup-and-replication-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2023-27532
  • CVE - 2023-27532
  • https://www.veeam.com/kb4424
  • 查看数 700
  • 已创建
  • 最后回复