A vulnerability allowing an authenticated user with the Backup Administrator role to perform remote code execution (RCE) in high availability (HA) deployments of Veeam Backup & Replication.
A vulnerability classified as CWE-94 (improper control of code generation) and CWE-693 (protection mechanism failure) allows an attacker with Backup Administrator role privileges to upload or execute malicious code in the context of a high availability deployment. The attack is possible remotely over the network without requiring user interaction on the victim's side. The elevated scope (Scope: Changed) indicates that the impact of the attack may extend beyond the directly vulnerable component.
An attacker can gain full control over the system — including complete access to stored backup data and the ability to modify or destroy data (high confidentiality, integrity, and availability). In HA environments, the impact may affect multiple cluster nodes.
Apply patches available from the vendor according to the references: https://www.veeam.com/kb4831. Additionally, it is recommended to restrict access to the Backup Administrator role only to trusted and necessary accounts, and to monitor the activity of privileged users in HA environments.
Veeam Backup & Replication in high availability (HA) configurations. Specific affected versions are indicated in the vendor references: https://www.veeam.com/kb4831
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HVeeam Backup \& Replication
APPVeeam13.0.0.496 – 13.0.1.1071
Related vulnerabilities
Krytyczne RCE przez deserialization w Veeam Backup & Replication
Veeam Backup & Replication — nieprawidłowa kontrola dostępu (RCE bez uwierzytelnienia)
RCE w Veeam Backup & Replication dla uwierzytelnionego użytkownika domenowego
RCE dla uwierzytelnionego użytkownika domenowego w Veeam Backup & Replication
RCE w Veeam Backup & Replication dla uwierzytelnionych użytkowników domenowych