logo

Veeam Backup & Replication CVE-2023-27532 Response

ID: 02be2d81-78fb-5d4d-bf2e-2abc561ea63f

STIX ID: report--02be2d81-78fb-5d4d-bf2e-2abc561ea63f

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress analyzed CVE-2023-27532 in Veeam Backup & Replication, an unauthenticated API flaw (default port 9401) that exposes encrypted credentials which can be decrypted and may also allow remote code execution; they found ~7,500 vulnerable hosts in their install base, reproduced a proof-of-concept, and recommend immediate patching to versions V12.0.0.1420 or V11.0.1.1261 and enabling API logging for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.