Loading HuntDB...

Veeam Backup & Replication Remote Code Execution Vulnerability

Added Dec. 13, 2022 Due Jan. 3, 2023 CVE-2022-26500
Overdue Veeam / Backup & Replication Known Ransomware Use CWE-22

Description

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
8 months, 1 week ago