CVE-2023-27532
Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability
Description
CVE-2023-27532 is a missing authentication vulnerability in Veeam Backup & Replication that allows an unauthenticated attacker to obtain encrypted credentials stored in the configuration database. By exploiting this security flaw, attackers can gain access to backup infrastructure hosts, potentially compromising the entire backup environment. This vulnerability is particularly dangerous because CISA has confirmed active exploitation in the wild and it has been linked to ransomware campaigns. With an EPSS score of 82.7%, indicating a very high probability of exploitation, organizations running Veeam Backup & Replication should treat CVE-2023-27532 as an urgent security priority.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| veeam | veeam backup \& replication | < 11.0.1.1261; 11.0.1.1261; 12.0.0.1420 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
- https://www.veeam.com/kb4424(Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-27532(US Government Resource)
Weakness Type
CWE-306: Missing Authentication for Critical Function
In the context of CVE-2023-27532, the Veeam Backup & Replication component exposes a critical function that provides access to encrypted credentials without requiring proper authentication. This missing authentication weakness allows any network-accessible attacker to retrieve sensitive credential data from the configuration database, bypassing intended access controls.
Learn more: CWE-306 — Missing Authentication for Critical Function
Impact Analysis
CVE-2023-27532 carries a CVSS v3.1 score of 7.5 (High severity) and poses a significant risk to organizations relying on Veeam Backup & Replication for data protection. The vulnerability is remotely exploitable without physical access, requires no special conditions to exploit (low attack complexity), needs no authentication, and demands no user interaction — making it trivially exploitable by any network-adjacent threat actor. Confidentiality (High): The primary impact is the exposure of encrypted credentials stored in the Veeam configuration database, which can be leveraged to authenticate against backup infrastructure hosts and potentially access all backed-up data. While integrity and availability are not directly impacted by the credential extraction itself, the stolen credentials serve as a stepping stone for further compromise. Ransomware risk: This vulnerability has been associated with known ransomware operations, meaning attackers are actively using it to gain initial access for deploying ransomware against backup infrastructure — a particularly devastating attack vector since backups are the primary defense against ransomware.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2023-27532 in the wild by adding it to the Known Exploited Vulnerabilities catalog, with a remediation deadline of September 12, 2023. Critically, this vulnerability is known to be used in ransomware campaigns, making it an immediate threat to organizations with exposed Veeam Backup & Replication instances. The EPSS score of 82.7% (99th percentile) indicates near-certain exploitation activity, further underscoring the urgency of remediation. While no public exploit code is directly linked in the NVD references, the high EPSS score and confirmed ransomware usage demonstrate that exploitation tools are readily available to threat actors.
Remediation
- Apply vendor mitigations immediately. Follow CISA's required action: apply mitigations per Veeam's instructions as detailed in KB4424, or discontinue use of the product if mitigations are unavailable. The remediation deadline set by CISA was September 12, 2023.
- Upgrade Veeam Backup & Replication to the latest patched version that addresses CVE-2023-27532. Consult the Veeam KB4424 advisory for specific version guidance and patch availability.
- Restrict network access to the Veeam Backup & Replication management interface. Ensure that the Veeam service ports are not exposed to untrusted networks and implement firewall rules to limit access to authorized management hosts only.
- Monitor for indicators of compromise by reviewing authentication logs on backup infrastructure hosts for unauthorized access attempts. Check for unusual credential usage patterns, unexpected backup job modifications, or signs of lateral movement from the Veeam server.
- Rotate all credentials stored in the Veeam configuration database, including credentials for backup repositories, managed servers, and cloud service accounts, as these may have already been exfiltrated by attackers.
Technical Details
CVE-2023-27532 exploits a missing authentication weakness (CWE-306) in a Veeam Backup & Replication component that handles credential storage and retrieval. The vulnerability allows an unauthenticated attacker to send specially crafted requests over the network to extract encrypted credentials from the Veeam configuration database. As reflected in the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), the attack is network-based with low complexity, requires no privileges or user interaction, and results in a high confidentiality impact while leaving integrity and availability unaffected. The critical function that should require authentication — credential retrieval from the configuration database — is accessible without any form of authentication verification, allowing attackers to directly obtain the encrypted credentials that Veeam uses to connect to backup infrastructure hosts.
Frequently Asked Questions
Is CVE-2023-27532 being actively exploited?
Yes, CVE-2023-27532 is being actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities catalog and confirmed that it is used in ransomware campaigns. The EPSS score of 82.7% (99th percentile) further confirms widespread exploitation activity.
What products are affected by CVE-2023-27532?
CVE-2023-27532 affects Veeam Backup & Replication. All versions prior to the patch referenced in Veeam KB4424 are considered vulnerable. Organizations should consult the vendor advisory for specific version details and patch availability.
How do I fix CVE-2023-27532?
Apply the patches provided by Veeam as detailed in KB4424. Additionally, restrict network access to the Veeam management interface, rotate all credentials stored in the configuration database, and monitor backup infrastructure for signs of unauthorized access. See the Remediation section for detailed steps.
How severe is CVE-2023-27532?
CVE-2023-27532 is rated High severity with a CVSS v3.1 score of 7.5. It ranks in the 99th percentile for exploitation probability (EPSS). The combination of confirmed ransomware usage, active exploitation, and the critical nature of backup infrastructure makes this vulnerability extremely urgent to address.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.