Loading...
Loading...
CVE-2025-23114 A vulnerability within the Veeam Updater component that allows an attacker to utilize a Man-in-the-Middle attack to execute arbitrary code on the affected appliance server with root-level permissions. Severity: CriticalCVSS v3.1 Score: 9.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HSource: Reported by @putsi via HackerOne. Affected Products Current Releases The following product's current release is affected by this vulnerability: Veeam Backup for Salesforce — 3.1 and older Previous Releases The following product's older releases utilize an older Veeam Updater component that was also found to be affected.As noted below each entry, the most recent version of each of these appliances is not affected. Therefore, if Veeam Backup & Replication is running version 12.3, and the appliances for these applications have been updated, they will be running a current and unaffected version. Veeam Backup for Nutanix AHV — 5.0 | 5.1Note: Version 6 (released on 2024-08-24 alongside VBR 12.2) and higher are unaffected by this vulnerability. Veeam Plug-In for AWS — 6a | 7Note: The most recent version (v8), released on 2024-07-02, is unaffected by this vulnerability. Veeam Plug-In for Microsoft Azure — 5a | 6Note: The most recent version (v7), released on 2024-07-02, is unaffected by this vulnerability. Veeam Plug-In for Google Cloud — 4 | 5Note: The most recent version (v6), released on 2024-12-03, is unaffected by this vulnerability. Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization — 3 | 4.0 | 4.1Note: Version 5 (released on 2024-08-24 alongside VBR 12.2) and higher are unaffected by this vulnerability.
Veeam Backup for Salesforce The vulnerability was resolved in Veeam Updater component version 9.0.0.1124. Checking for Updates using the built-in Veeam Updater to update the Veeam Updater component. View updates history, and check the Veeam Updater version shown in the top-right corner.
If a Veeam Backup & Replication deployment is not protecting AWS, Google Cloud, Microsoft Azure, Nutanix AHV, or Oracle Linux VM/Red Hat Virtualization, such a deployment is not impacted by the vulnerability discussed in this article. You can verify if Veeam Backup & Replication manages any of these affected backup appliances by checking the Backup Infrastructure > Managed Servers list for any of the following entry types: Nutanix AHV / Nutanix Prism Central / Nutanix AHV Cluster AWS backup appliance Microsoft Azure backup appliance Google Cloud backup appliance oVirt KVM Manager
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.