Vulnerability Details CVE-2020-15518
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2020-15518
-
cpe:2.3:a:veeam:veeam_availability_suite:*
-
cpe:2.3:a:veeam:veeam_backup_&_replication:5.0.2.230
-
cpe:2.3:a:veeam:veeam_backup_&_replication:8.0.0.2030
-
cpe:2.3:a:veeam:veeam_backup_&_replication:9.5.0.1536
-
cpe:2.3:a:veeam:veeam_backup_&_replication:9.5.4.2615