All vulnerabilities documented in this article were resolved in Veeam Backup & Replication 13.0.1.1071.
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
Severity: High
CVSS v3.1 Score: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: Discovered during internal testing.
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
Severity: Medium
CVSS v3.1 Score: 6.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Source: Discovered during internal testing.
This vulnerability allows a Backup or Tape Operator to write files as root.
Severity: High
CVSS v3.1 Score: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: Discovered during internal testing.
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
Adjusted Severity*: High
CVSS Severity: Critical
CVSS v3.1 Score: 9.0CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Source: Discovered during internal testing.
*Reason for Adjustment: The Backup and Tape Operator roles are considered highly privileged roles and should be protected as such. Following Veeam's recommended Security Guidelines further reduces the opportunity for exploitability. Due to these factors affecting the temporal and environmental vectors of CVSS, Veeam has adjusted its response to this vulnerability to align with that of a High severity rating.
These vulnerabilities were fixed starting with the following build:
If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case