CVE-2025-23121

A

vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

References
Link Resource
https://www.veeam.com/kb4743 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*

History

15 Jul 2025, 14:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.9
v2 : unknown
v3 : 8.8
References () https://www.veeam.com/kb4743 - () https://www.veeam.com/kb4743 - Patch, Vendor Advisory
CPE cpe:2.3:a:veeam:veeam_backup_\&_replication:*:*:*:*:*:*:*:*
First Time Veeam veeam Backup \& Replication
Veeam

23 Jun 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad que permite la ejecución remota de código (RCE) en el servidor de respaldo por parte de un usuario de dominio autenticado
CWE CWE-94

19 Jun 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-19 00:15

Updated : 2025-07-15 14:01


NVD link : CVE-2025-23121

Mitre link : CVE-2025-23121

CVE.ORG link : CVE-2025-23121


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')