QID 376101

Date Published: 2023-11-02

QID 376101: Veeam Backup and Replication Deserialization Logic Vulnerability

Veeam Backup and Replication is a proprietary backup app developed by Veeam for virtual environments built on VMware vSphere, Nutanix AHV, and Microsoft Hyper-V hypervisors.

Veeam Backup and Replication mishandles deserialization during Microsoft .NET remoting.

Affected Version:
Veeam Backup and Replication 11 before 11.0.0.837 P20210525

QID detection Logic (Authenticated) :
This QID checks for vulnerable version of Veeam Backup and Replication

Successful exploit could compromise confidentiality, integrity and availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to install or update to Veeam Backup and Replication version 11 kb4126
    Vendor References

    CVEs related to QID 376101

    Software Advisories
    Advisory ID Software Component Link
    kb4126 URL Logo www.veeam.com/kb4126