ID:9593 - Exploit for Missing authentication for critical function in Backup & Replication - CVE-2023-27532
Published: March 4, 2024
Backup & Replication
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to missing authorization within the Veeam.Backup.Service.exe. A remote attacker can connect to the affected service that is listening on port 9401/TCP, obtain encrypted credentials stored in the configuration database and use this information to access the backup infrastructure hosts.