Veeam Backup & Replication Remote Code Execution Vulnerability – CVE-2022-26500 | CVE-2022-26501

Veeam Backup & Replication Remote Code Execution Vulnerability – CVE-2022-26500 | CVE-2022-26501

Release Date – Dec 13, 2022

CVE Details – CVE-2022-26500 | CVE-2022-26501

Alert Severity – Critical

Affected Products – Veeam Backup & Replication | 9.5 | 10 | 11

Description –

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

Mitigation/Solution –

Apply the patches available from VEEAM.

All new deployments of Veeam Backup & Replication version 11a and 10a installed using the ISO images dated 20220302 or later are not vulnerable.

Add a Comment

Your email address will not be published.