CVE-2022-26500

Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
veeamveeam_backup_\&_replication
10.0.0.4442 ≤
𝑥
< 10.0.1.4854
veeamveeam_backup_\&_replication
11.0.0.825 ≤
𝑥
< 11.0.1.1261
veeamveeam_backup_\&_replication
9.5.0.1536
veeamveeam_backup_\&_replication
9.5.4.2615
veeamveeam_backup_\&_replication
10.0.1.4854
veeamveeam_backup_\&_replication
10.0.1.4854:p20201202
veeamveeam_backup_\&_replication
10.0.1.4854:p20210609
veeamveeam_backup_\&_replication
11.0.1.1261
veeamveeam_backup_\&_replication
11.0.1.1261:p20211123
veeamveeam_backup_\&_replication
11.0.1.1261:p20211211
𝑥
= Vulnerable software versions