Veeam Log Audit
Inspect C:\ProgramData\Veeam\Backup\Veeam.Backup.Service.log for unexpected connection origins on port 9401:
Connecting to remote service on port 9401 from [suspicious_ip].
Veeam Backup & Replication (Veeam.Backup.Service.exe / TCP 9401) CVSS v3.1 rates CVE-2023-27532 at 7.5 (HIGH, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The Hermes Threat Score elevates operational risk to 91 (HIGH) reflecting extensive ransomware weaponization (FIN7, Akira, Medusa) and presence in offensive AI toolkits.
Software platform affected by security vulnerabilities and agentic attack patterns.
“Confirmed security vulnerability in Veeam Backup & Replication documented in Hermes dossier.”
Adversaries search compromise victims for unsecured credentials in files, environment variables, or memory.
“Attack execution telemetry aligns with MITRE ATT&CK technique T1552.”
| Parameter | Technical Specification | Threat Intelligence Context |
|---|---|---|
| CVE Identifier | CVE-2023-27532 | Veeam Security Advisory KB4424 & CISA KEV |
| Affected Product | veeam:backup_and_replication | Enterprise Backup, Recovery & Disaster Recovery Platform |
| Vulnerable Component | Veeam Backup Service (TCP 9401) | .NET Remoting / WCF Service Endpoint |
| Weakness Class | CWE-306: Missing Authentication for Critical Function | Broken Authentication / Sensitive Data Exposure |
| CVSS v3.1 Score | 7.5 (HIGH / Hermes Score 91) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Fixed Versions | 12.0.0.1420 P20230319, 11.0.0.837 P20230321 | Official Vendor Hotfix Releases |
| MITRE ATT&CK | T1552.001 - Credentials in Files, T1078 - Valid Accounts | Credential Access / Privilege Escalation |
| Forensic Cross-Reference | Veeam Backup Vulnerability Matrix | Forensic DFIR triage for backup server intrusions |
The Veeam Backup Service (Veeam.Backup.Service.exe) listens on TCP port 9401 by default. It exposes an internal communications endpoint designed to allow auxiliary backup components to retrieve configuration records.
However, the endpoint lacked authentication enforcement:
Credentials table within the Veeam backend Microsoft SQL Server database.9401/TCP.Veeam.Backup.Service.exe to dump the configuration database.SharpVeeamDecryptor or VeeamDumper.Veeam Log Audit
Inspect C:\ProgramData\Veeam\Backup\Veeam.Backup.Service.log for unexpected connection origins on port 9401:
Connecting to remote service on port 9401 from [suspicious_ip].
Process Telemetry
Monitor for processes querying the Veeam SQL database or executing VeeamDumper.exe or SharpVeeamDecryptor.exe.