« Volver al listado

CVE-2022-26504

Estado: ModificadaAlta (8.8)—

Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-26504",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
          "authentication": "SINGLE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-17T21:15:08.273",
  "references": [
    {
      "url": "https://veeam.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.veeam.com/kb4290",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://veeam.com",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.veeam.com/kb4290",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Center Virtual Machine Manager (SCVMM) allows attackers execute arbitrary code via Veeam.Backup.PSManager.exe"
    },
    {
      "lang": "es",
      "value": "Una autenticación inapropiada en Veeam Backup & Replication versiones 9.5U3, 9.5U4,10.x y 11.x, componente usado para Microsoft System Center Virtual Machine Manager (SCVMM) permite a atacantes ejecutar código arbitrario por medio del archivo Veeam.Backup.PSManager.exe"
    }
  ],
  "lastModified": "2026-06-17T04:35:19.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "837D781D-E21B-458C-8D4A-59949CE4D580",
              "versionEndExcluding": "10.0.1.4854",
              "versionStartIncluding": "10.0.0.4442"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD0C1BCB-A018-4425-AC3D-0CE6EAEF372F",
              "versionEndExcluding": "11.0.1.1261",
              "versionStartIncluding": "11.0.0.825"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:9.5.0.1536:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BC7D0C1-0A10-4704-B8A0-ADFB8B2BA1BB"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:9.5.4.2615:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D5BA0C4-F689-4B0E-BBB5-051DEDF40721"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:10.0.1.4854:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12E8F01F-4E41-46F0-94BC-DD5174DDF393"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:10.0.1.4854:p20201202:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0417823-7418-4294-BE57-0304772DFE39"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:10.0.1.4854:p20210609:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06BE9B78-075C-48E6-817A-5E0A89983EBC"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:10.0.1.4854:p20220304:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0209ABC3-BF7B-4051-A836-9F9A650B3582"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC28D606-0A9B-46E5-A88C-8041357979DB"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:p20211123:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8158D6BC-2041-4600-B935-AD928621D987"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:p20211211:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54A5147A-341A-4790-AAA8-DF2648423C50"
            },
            {
              "criteria": "cpe:2.3:a:veeam:veeam_backup_\\&_replication:11.0.1.1261:p20220302:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F5A2E58-F9C3-4A65-A83B-C86C970A01D2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}