nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-26504 CVE-2022-26504
HIGHRansomware
Veeam veeam_backup_\&_replication Improper Authentication
Record summary
CVE-2022-26504 has a selected CVSS score of 8.8 (high). VulnCheck reports CVE-2022-26504 use in known ransomware campaigns.
Description
Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 24, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
veeam_backup_\&_replicationBrowse Veeam / veeam_backup_\&_replication | VulnCheck | Version data not supplied | |
References
3veeam.com
https://veeam.com/ veeam.com
https://www.veeam.com/kb4290