Database/Control plane, storage & DevOps
Veeam Backup & Replication: Authenticated domain user achieves remote code execution on the Backup Server
CVSS 8.8CVE-2025-23121Control plane, storage & DevOpscurated
Impact
Authenticated domain user achieves remote code execution on the Backup Server
Who can reach it
Network (remote)
What to do
Control-plane: patch; workgroup-isolate the backup infrastructure
References
Related entries
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedCVE-2023-27532 · Veeam Backup & ReplicationHigh
- Veeam Backup & Replication: Deserialization of untrusted dataCVE-2024-40711 · Veeam Backup & ReplicationCritical
- Veeam Backup & Replication: Remote code execution reachable by any domain user on a domain-joined backup serverCVE-2025-23120 · Veeam Backup & ReplicationHigh
- Dell OpenManage Network Integration (RADIUS auth bypass): An attacker on the local network forges a valid RADIUS AcceptCVE-2025-36593 · Dell OpenManage Network Integration (RADIUS auth bypass)High
- Commvault Web Server: Remote authenticated attacker creates and executes webshellsCVE-2025-3928 · Commvault Web ServerHigh
- Linux iommu/amd - race while increasing host page table level: The AMD IOMMU host page table implementation supportsCVE-2025-39961 · Linux iommu/amd - race while increasing host page table levelHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.