Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
References
History

Tue, 14 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-918

Tue, 14 Jan 2025 02:00:00 +0000

Type Values Removed Values Added
Description Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2025-01-14T01:46:14.729Z

Updated: 2025-01-14T15:51:53.014Z

Reserved: 2025-01-10T19:05:52.771Z

Link: CVE-2025-23082

cve-icon Vulnrichment

Updated: 2025-01-14T15:51:48.647Z

cve-icon NVD

Status : Received

Published: 2025-01-14T02:15:08.163

Modified: 2025-01-14T16:15:36.200

Link: CVE-2025-23082

cve-icon Redhat

No data.