PT-2023-1918 · Veeam · Veeam Backup & Replication

·

CVE-2023-27532

·

Published

2023-03-07

·

Updated

2026-07-13

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Veeam Backup & Replication versions V11 through V12
Description A vulnerability in the Veeam Backup & Replication component allows an unauthenticated user within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This issue is caused by a missing authentication check for a critical function in the Veeam.Backup.Service.exe executable. An attacker can abuse an unprotected API endpoint to retrieve credentials in cleartext, which may lead to unauthorized access to backup infrastructure hosts and remote code execution (RCE) through additional API calls. This flaw has been exploited in the wild by the Qilin (Agenda) ransomware group to gain initial access to environments, including a significant attack on the Asahi Group in September 2025. It is estimated that at least 7,500 out of 2 million hosts running the software remain vulnerable.
Recommendations Update Veeam Backup & Replication V11 to the security update released on March 7. Update Veeam Backup & Replication V12 to the security update released on March 7. For installations with unsupported versions, apply the provided temporary workaround to protect the system.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01528
CVE-2023-27532
VEEAMBAR_CVE2023_27532

Affected Products

Veeam Backup & Replication