CVE-2022-26500
Veeam Backup & Replication Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
YesDecision
Descriptions
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
Una limitación inapropiada de los nombres de las rutas en Veeam Backup & Replication versiones 9.5U3, 9.5U4,10.x y 11.x, permite a usuarios remotos autenticados acceder a funciones internas de la API que permiten a atacantes cargar y ejecutar código arbitrario
The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-06 CVE Reserved
- 2022-03-17 CVE Published
- 2022-12-13 Exploited in Wild
- 2023-01-03 KEV Due Date
- 2024-08-02 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://veeam.com | 2024-05-09 | |
https://www.veeam.com/kb4288 | 2024-05-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | >= 10.0.0.4442 < 10.0.1.4854 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version " >= 10.0.0.4442 < 10.0.1.4854" | - |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | >= 11.0.0.825 < 11.0.1.1261 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version " >= 11.0.0.825 < 11.0.1.1261" | - |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 9.5.0.1536 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "9.5.0.1536" | - |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 9.5.4.2615 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "9.5.4.2615" | - |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 10.0.1.4854 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "10.0.1.4854" | - |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 10.0.1.4854 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "10.0.1.4854" | p20201202 |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 10.0.1.4854 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "10.0.1.4854" | p20210609 |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 11.0.1.1261 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "11.0.1.1261" | - |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 11.0.1.1261 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "11.0.1.1261" | p20211123 |
Affected
| ||||||
Veeam Search vendor "Veeam" | Veeam Backup \& Replication Search vendor "Veeam" for product "Veeam Backup \& Replication" | 11.0.1.1261 Search vendor "Veeam" for product "Veeam Backup \& Replication" and version "11.0.1.1261" | p20211211 |
Affected
|