| KB ID: | 4709 |
| Product: | Veeam Plug-In for Microsoft Azure | 7 |
| Published: | 2025-01-13 |
| Last Modified: | 2025-01-29 |
This article documents a vulnerability discovered in the Veeam Plug-In for Microsoft Azure backup appliance, which is used by Veeam Backup & Replication to protect Microsoft Azure workloads.
If a Veeam Backup & Replication deployment is not protecting Microsoft Azure workloads, such a deployment is not impacted by the vulnerability discussed in this article.
You can verify if Veeam Backup & Replication manages a Veeam Backup for Microsoft Azure backup appliance by checking the Backup Infrastructure > Managed Servers list for any 'Microsoft Azure backup appliance' type entries.
A vulnerability that may allow an attacker to utilize Server-Side Request Forgery (SSRF) to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affects Veeam Plug-In for Microsoft Azure 7.1.0.22 and all earlier versions.
Severity: High
CVSS v3.1 Score: 7.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: Discovered during internal testing.
If this KB article did not resolve your issue or you need further assistance with Veeam software, please create a Veeam Support Case.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case