{"cveID":"CVE-2023-27532","vendorProject":"Veeam","product":"Backup & Replication","vulnerabilityName":"Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability","dateAdded":"2023-08-22","shortDescription":"Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-09-12","knownRansomwareCampaignUse":"Known","notes":"https://www.veeam.com/kb4424;  https://nvd.nist.gov/vuln/detail/CVE-2023-27532","cwes":["CWE-306"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-27532","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"exploitation_technique","capability_group":"auth_missing","comments":"CVE-2023-27532 is a vulnerability in their backup & replication servers exposed online which allows unauthenticated users to request encrypted credentials. Public reporting has indicated that various ransomware groups have exploited vulnerability to gain access and crash the backup infrastructure hosts, extract stored encrypted credentials, and deploy additional tools. ","references":["https://www.theregister.com/2024/07/11/estate_ransomware_veeam_bug/","https://www.securityweek.com/year-old-veeam-vulnerability-exploited-in-fresh-ransomware-attacks/","https://www.group-ib.com/blog/estate-ransomware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-27532","technique":"T1059.003","technique_name_at_mapping":"Windows Command Shell","mapping_type":"primary_impact","capability_group":"auth_missing","comments":"CVE-2023-27532 is a vulnerability in their backup & replication servers exposed online which allows unauthenticated users to request encrypted credentials. Public reporting has indicated that various ransomware groups have exploited vulnerability to gain access and crash the backup infrastructure hosts, extract stored encrypted credentials, and deploy additional tools. ","references":["https://www.theregister.com/2024/07/11/estate_ransomware_veeam_bug/","https://www.securityweek.com/year-old-veeam-vulnerability-exploited-in-fresh-ransomware-attacks/","https://www.group-ib.com/blog/estate-ransomware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-27532","technique":"T1087","technique_name_at_mapping":"Account Discovery","mapping_type":"secondary_impact","capability_group":"auth_missing","comments":"CVE-2023-27532 is a vulnerability in their backup & replication servers exposed online which allows unauthenticated users to request encrypted credentials. Public reporting has indicated that various ransomware groups have exploited vulnerability to gain access and crash the backup infrastructure hosts, extract stored encrypted credentials, and deploy additional tools. ","references":["https://www.theregister.com/2024/07/11/estate_ransomware_veeam_bug/","https://www.securityweek.com/year-old-veeam-vulnerability-exploited-in-fresh-ransomware-attacks/","https://www.group-ib.com/blog/estate-ransomware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-27532","technique":"T1087.001","technique_name_at_mapping":"Local Account","mapping_type":"secondary_impact","capability_group":"auth_missing","comments":"CVE-2023-27532 is a vulnerability in their backup & replication servers exposed online which allows unauthenticated users to request encrypted credentials. Public reporting has indicated that various ransomware groups have exploited vulnerability to gain access and crash the backup infrastructure hosts, extract stored encrypted credentials, and deploy additional tools. ","references":["https://www.theregister.com/2024/07/11/estate_ransomware_veeam_bug/","https://www.securityweek.com/year-old-veeam-vulnerability-exploited-in-fresh-ransomware-attacks/","https://www.group-ib.com/blog/estate-ransomware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-27532","technique":"T1486","technique_name_at_mapping":"Data Encrypted for Impact","mapping_type":"secondary_impact","capability_group":"auth_missing","comments":"CVE-2023-27532 is a vulnerability in their backup & replication servers exposed online which allows unauthenticated users to request encrypted credentials. Public reporting has indicated that various ransomware groups have exploited vulnerability to gain access and crash the backup infrastructure hosts, extract stored encrypted credentials, and deploy additional tools. ","references":["https://www.theregister.com/2024/07/11/estate_ransomware_veeam_bug/","https://www.securityweek.com/year-old-veeam-vulnerability-exploited-in-fresh-ransomware-attacks/","https://www.group-ib.com/blog/estate-ransomware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-27532","technique":"T1555","technique_name_at_mapping":"Credentials from Password Stores","mapping_type":"secondary_impact","capability_group":"auth_missing","comments":"CVE-2023-27532 is a vulnerability in their backup & replication servers exposed online which allows unauthenticated users to request encrypted credentials. Public reporting has indicated that various ransomware groups have exploited vulnerability to gain access and crash the backup infrastructure hosts, extract stored encrypted credentials, and deploy additional tools. ","references":["https://www.theregister.com/2024/07/11/estate_ransomware_veeam_bug/","https://www.securityweek.com/year-old-veeam-vulnerability-exploited-in-fresh-ransomware-attacks/","https://www.group-ib.com/blog/estate-ransomware/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Windows Command Shell","name_at_mapping":"Windows Command Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":46,"has_detection_strategy":true},{"id":"T1087","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Account Discovery","name_at_mapping":"Account Discovery","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":16,"has_detection_strategy":true},{"id":"T1087.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Local Account","name_at_mapping":"Local Account","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":13,"has_detection_strategy":true},{"id":"T1133","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"External Remote Services","name_at_mapping":"External Remote Services","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1486","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data Encrypted for Impact","name_at_mapping":"Data Encrypted for Impact","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":16,"has_detection_strategy":true},{"id":"T1555","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Credentials from Password Stores","name_at_mapping":"Credentials from Password Stores","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":8,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}