LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-27532: Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 22, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 12, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-27532 to its Known Exploited Vulnerabilities catalog on Aug 22, 2023, with a federal patch deadline of Sep 12, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure…

CVE-2023-27532 is a missing-authentication flaw in the Cloud Connect component of Veeam Backup & Replication. An unauthenticated user who can reach the backup infrastructure network perimeter can obtain encrypted credentials stored in the configuration database, which may allow further access to backup infrastructure hosts. The vulnerability has been used by ransomware operators, so organizations running this product should treat it as a priority for inventory, patching, and monitoring.

Public detail is limited to the CISA description and the CWE classification; exact product versions, CVSS scores, and exploit mechanics must be confirmed against the vendor advisory. The required action is to apply mitigations per vendor instructions or discontinue use if mitigations are unavailable.

How it works

The weakness is CWE-306: missing authentication for a critical function. In the Cloud Connect component, a critical operation that should require authentication does not properly enforce it. An attacker who is already operating inside the backup infrastructure network perimeter can invoke that function without credentials and retrieve encrypted credentials from the configuration database.

Those credentials can then be used to expand access to backup infrastructure hosts. No further exploit mechanics, payloads, or version-specific behavior are provided in the available facts; defenders should treat any unauthenticated access path to Cloud Connect management or configuration interfaces as in scope and validate details against the vendor advisory.

Am I affected? How to find it in your systems

Veeam Backup & Replication with the Cloud Connect component is typically deployed on dedicated backup servers or appliances that manage remote or multi-tenant backup traffic. Inventory every host running Veeam Backup & Replication and determine whether Cloud Connect is enabled or installed.

Telemetry signs of exploitation may include unexpected queries or connections to Cloud Connect services from non-management hosts, anomalous access to the configuration database, or subsequent authentication attempts using previously stored credentials. Correlate backup-server logs, authentication logs, and network flow data for such activity. Specific log signatures are not provided in the facts and must be derived from vendor guidance.

How to remediate

Apply the vendor update or mitigation named in the official advisory for CVE-2023-27532 as the primary remediation. Follow the CISA required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Document the change window and retain evidence of the applied update for audit and incident-response purposes.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that limit reachability and detect abuse of the missing-authentication path.

If your data may have been exposed

Actively exploited vulnerabilities of this class have been used by ransomware operators and can lead to full compromise of backup infrastructure and the data it protects. If you have evidence of unauthenticated access or credential theft, treat the incident as a potential breach: isolate affected hosts, preserve logs, rotate credentials, and engage incident response. You can also run a free exposure scan of your email addresses against known breach data to check whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVeeam · Backup & Replication
WeaknessCWE-306
Added to CISA KEVAug 22, 2023
Federal patch deadlineSep 12, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities