Database/Control plane, storage & DevOps
Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtained
CVSS 7.5CVE-2023-27532Control plane, storage & DevOpsKnown exploitedcurated
Impact
Encrypted credentials in the configuration database can be obtained -> access to backup infrastructure hosts
Who can reach it
Network (remote)
What to do
Control-plane: patch + rotate every credential the backup server held
References
Related entries
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverCVE-2025-23120 · Veeam Backup & ReplicationHigh
- Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup ServerCVE-2025-23121 · Veeam Backup & ReplicationHigh
- MinIO: Cluster returns all env vars incl. MINIO_SECRET_KEY and MINIO_ROOT_PASSWORDCVE-2023-28432 · MinIOHigh
- Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllers: An unauthenticated user can logCVE-2023-3127 · Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllersHigh
- AMD Radeon Graphics display driver - input validation: Improper input validation in the Radeon display driver letsCVE-2023-31320 · AMD Radeon Graphics display driver - input validationHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.