CVE-2025-23082: Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send...

7.2 CVSS

Description

Veeam Backup for Microsoft Azure is vulnerable to Server-Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

Classification

CVE ID: CVE-2025-23082

CVSS Base Severity: HIGH

CVSS Base Score: 7.2

Affected Products

Vendor: Veeam

Product: Backup for Microsoft Azure

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-12 (when was this score calculated)

References

https://www.veeam.com/kb4709

Timeline