#VU74001 Missing authentication for critical function in Backup & Replication - CVE-2023-27532
Published: March 24, 2023 / Updated: March 4, 2024
Backup & Replication
Veeam
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to missing authorization within the Veeam.Backup.Service.exe. A remote attacker can connect to the affected service that is listening on port 9401/TCP, obtain encrypted credentials stored in the configuration database and use this information to access the backup infrastructure hosts.