← לוח פגיעויות

CVE-2023-27532

גבוהה 7.5 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
78% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-306

מוצרים מושפעים

veeam: veeam backup \& replication

קישורים