logo

Veeam Backup & Replication Vulnerability Exposes Stored Credentials, No Auth Necessary

ID: d93af950-5778-56fe-8689-4150471ae7c5

STIX ID: report--d93af950-5778-56fe-8689-4150471ae7c5

Feed Name: Kudelski Security

Threat Score
70/100

Date Published: 2023-03-10

Date Updated: 2026-07-22

...
...

**CVE-2023-27532 — Veeam Backup & Replication:** A high-severity vulnerability affecting most Veeam Backup & Replication deployments (unless built from ISOs dated 20230223/20230227 or later) allows unauthenticated attackers with network access to retrieve credentials in cleartext via the product API (Veeam.Backup.Service.exe on TCP/9401); vendor patches and temporary mitigations (patch, or block TCP/9401 on all-in-one appliances) and detection guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.