Veeam Backup & Replication CVE-2023-27532 Response
ID: 02be2d81-78fb-5d4d-bf2e-2abc561ea63f
STIX ID: report--02be2d81-78fb-5d4d-bf2e-2abc561ea63f
Feed Name: Huntress Blog
Threat Score
Huntress analyzed CVE-2023-27532 in Veeam Backup & Replication, an unauthenticated API flaw (default port 9401) that exposes encrypted credentials which can be decrypted and may also allow remote code execution; they found ~7,500 vulnerable hosts in their install base, reproduced a proof-of-concept, and recommend immediate patching to versions V12.0.0.1420 or V11.0.1.1261 and enabling API logging for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
