PT-2023-1918 · Veeam · Veeam Backup & Replication
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Veeam Backup & Replication versions V11 through V12
Description
A vulnerability in the Veeam Backup & Replication component allows an unauthenticated user within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This issue is caused by a missing authentication check for a critical function in the
Veeam.Backup.Service.exe executable. An attacker can abuse an unprotected API endpoint to retrieve credentials in cleartext, which may lead to unauthorized access to backup infrastructure hosts and remote code execution (RCE) through additional API calls. This flaw has been exploited in the wild by the Qilin (Agenda) ransomware group to gain initial access to environments, including a significant attack on the Asahi Group in September 2025. It is estimated that at least 7,500 out of 2 million hosts running the software remain vulnerable.Recommendations
Update Veeam Backup & Replication V11 to the security update released on March 7.
Update Veeam Backup & Replication V12 to the security update released on March 7.
For installations with unsupported versions, apply the provided temporary workaround to protect the system.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veeam Backup & Replication