CVE-2025-23114: Veeam Backup For Aws
Critical severity, CVSS 9.0. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
Affected products
- Veeam Backup For Aws: from 7.0, up to and including 7.0
- Veeam Backup For Google Cloud: from 5.0, up to and including 5.0
- Veeam Backup For Microsoft Azure: from 6.0, up to and including 6.0
- Veeam Backup For Nutanix Ahv: from 5.1, up to and including 5.1
- Veeam Backup For Oracle Linux Virtualization Manager And Red Hat Virtualization: from 4.1, up to and including 4.1
- Veeam Backup For Salesforce: from 3.1, up to and including 3.1
Published 2025-02-05. Last modified 2026-06-17.