{"id":37061,"date":"2025-02-07T00:50:58","date_gmt":"2025-02-06T23:50:58","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=37061"},"modified":"2025-02-07T00:51:04","modified_gmt":"2025-02-06T23:51:04","slug":"critical-vulnerability-cve-2025-23114-in-veeam-updater","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2025\/02\/07\/critical-vulnerability-cve-2025-23114-in-veeam-updater\/","title":{"rendered":"Critical vulnerability CVE-2025-23114 in Veeam Updater"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2025\/02\/07\/kritische-schwachstelle-cve-2025-23114-in-veeam-updater\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]A critical vulnerability CVE-2025-23114 has been reported in the Veeam Updater. This vulnerability could be used to carry out man in the middle attacks. This affects various products from the provider. Veeam has published corresponding security updates to close the vulnerability.<\/p>\n<p><!--more--><\/p>\n<h2>Critical vulnerability CVE-2025-23114<\/h2>\n<p>I became aware of the vulnerability in question, CVE-2025-23114, which has been classified as critical with a CVSS score of 9.0, via the following tweets.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i.postimg.cc\/bwwH3f2h\/image.png\" alt=\"Veeam\" width=\"563\" height=\"515\" \/><\/p>\n<p>Veeam has published this <a href=\"https:\/\/www.veeam.com\/kb4712\" target=\"_blank\" rel=\"noopener\">security advisory (KB4712)<\/a> with vulnerability information as of February 4, 2025. Veeam has confirmed a Man in the Middle vulnerability in its Veeam Updater that affects the following products:<\/p>\n<p>Veeam Backup\u00a0<i>for Salesforce 3.1 and older<\/i><br \/>\nVeeam Backup\u00a0<i>for Nutanix AHV5.0 or 5.1 <\/i><br \/>\nVeeam Backup\u00a0<i>for AWS 6a or 7<\/i><br \/>\nVeeam Backup\u00a0<i>for Microsoft Azure 5a or 6<\/i><br \/>\nVeeam Backup\u00a0<i>for Google Cloud 4 or 5<\/i><br \/>\nVeeam Backup\u00a0<i>for Oracle Linux Virtualization Manager and Red Hat Virtualization 3, 4.0 or 4.1<\/i><\/p>\n<p>Affected versions should be updated as soon as possible. The following steps can be used to check whether you are affected:<\/p>\n<ul class=\"bbcode_list\">\n<li>Go to the <em>Configuration<\/em> page on your appliance (top right)<\/li>\n<li>Select <em>Support Information \u2192 Updates<\/em><\/li>\n<li>Click <em>Check and View Updates<\/em><\/li>\n<li>Goto <em>History-Tab<\/em><\/li>\n<\/ul>\n<p>The update can be carried out via the Auto-Updater. The risk of being attacked during the auto-update process should be low.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]A critical vulnerability CVE-2025-23114 has been reported in the Veeam Updater. This vulnerability could be used to carry out man in the middle attacks. This affects various products from the provider. Veeam has published corresponding security updates to close the &hellip; <a href=\"https:\/\/borncity.com\/win\/2025\/02\/07\/critical-vulnerability-cve-2025-23114-in-veeam-updater\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,1547],"tags":[69,1544],"class_list":["post-37061","post","type-post","status-publish","format-standard","hentry","category-security","category-software","tag-security","tag-software"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/37061","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=37061"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/37061\/revisions"}],"predecessor-version":[{"id":37062,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/37061\/revisions\/37062"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=37061"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=37061"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=37061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}