2023-03-02 18:00:40 +00:00
{
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"data_version" : "4.0" ,
"CVE_data_meta" : {
"ID" : "CVE-2023-27532" ,
2023-03-10 22:00:37 +00:00
"ASSIGNER" : "support@hackerone.com" ,
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "n/a" ,
"product" : {
"product_data" : [
{
"product_name" : "Veeam Backup & Replication" ,
"version" : {
"version_data" : [
{
"version_value" : "Fixed Versions: v12 (build 12.0.0.1420 P20230223)"
} ,
{
"version_value" : "11a (build 11.0.1.1261 P20230227)"
}
]
}
}
]
}
}
]
}
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "Missing Authentication for Critical Function (CWE-306)"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"refsource" : "MISC" ,
"name" : "https://www.veeam.com/kb4424" ,
"url" : "https://www.veeam.com/kb4424"
}
]
2023-03-02 18:00:40 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2023-03-10 22:00:37 +00:00
"value" : "Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts."
2023-03-02 18:00:40 +00:00
}
]
}
}