March 13, 2023
A vulnerability been found in Veeam Backup & Replication that enables an unauthenticated user to request encrypted credentials, which can give them access to server hosts used for backup infrastructure.
Veeam.Backup.Service.exe
(uses port TCP 9401
) can be exploited and allow an unauthenticated user to request encrypted credentials.
https://www.veeam.com/kb4424