Improper Authentication in Veeam Backup & Replication for Microsoft SCVMM
CVE-2022-26504

8.8HIGH

Key Information:

Vendor

Veeam

Vendor
CVE Published:
17 March 2022

What is CVE-2022-26504?

Veeam Backup & Replication, a solution widely used for backup and recovery by businesses leveraging Microsoft System Center Virtual Machine Manager (SCVMM), has a vulnerability stemming from improper authentication. This flaw affects various versions, allowing attackers to potentially execute arbitrary code through the vulnerable Veeam.Backup.PSManager.exe component. Organizations should address this security issue promptly to safeguard their data integrity and system reliability. Users are encouraged to consult Veeam’s official resources for mitigation techniques and to stay updated with patches.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.