High8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

PT-2022-09: Insufficient validation of file paths and Path Traversal in Veeam Backup & Replication

Error type:

  • CWE-22:Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Severity (CVSSv3.1): 8.8 (high)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity (CVSSv4.0): 8.7 (high)

Description:

The vulnerability was identified in Veeam Backup & Replication versions 9.5, 10, 11.

The discovered vulnerability allows an attaker to perform an NTLM-relay attack on behalf of the account under which the service is running, uploading arbitrary files from arbitrary paths to the VBR server, downloading arbitrary files from the VBR server.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 12.03.2022

Recommendations:

  • Update to version ,
  • For Veeam Backup & Replication 9.5, please to a supported product version

Additional information:

Researcher: Nikita Petrov (Positive Technologies)

Identifiers:

CVE-2022-26500

BDU:2022-01267

Vendor:

Veeam Software

Vulnerable product:

Veeam Backup & Replication

Vulnerable versions:

9.5, 10, 11