Show plain JSON{"id": "CVE-2023-27532", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2023-03-10T22:15:10.557", "references": [{"url": "https://www.veeam.com/kb4424", "tags": ["Vendor Advisory"], "source": "support@hackerone.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-306"}]}, {"type": "Secondary", "source": "support@hackerone.com", "description": [{"lang": "en", "value": "CWE-306"}]}], "descriptions": [{"lang": "en", "value": "Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts."}], "lastModified": "2024-05-09T18:37:54.573", "cisaActionDue": "2023-09-12", "cisaExploitAdd": "2023-08-22", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4AC06A80-CAA8-45A4-BCA3-A36D56F70B39"}, {"criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC28D606-0A9B-46E5-A88C-8041357979DB"}, {"criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:p20211123:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8158D6BC-2041-4600-B935-AD928621D987"}, {"criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:p20211211:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54A5147A-341A-4790-AAA8-DF2648423C50"}, {"criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:p20220302:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F5A2E58-F9C3-4A65-A83B-C86C970A01D2"}, {"criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:12.0.0.1420:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA570EC1-4A95-4AD3-8E8C-087769F95F02"}], "operator": "OR"}]}], "sourceIdentifier": "support@hackerone.com", "cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.", "cisaVulnerabilityName": "Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability"}