This article documents a vulnerability discovered in the Veeam Backup for Microsoft Azure backup appliance, which is used by Veeam Backup & Replication to protect Microsoft Azure workloads.
If a Veeam Backup & Replication deployment is not protecting Microsoft Azure workloads, such a deployment is not impacted by the vulnerability discussed in this article.
You can verify if Veeam Backup & Replication manages a Veeam Backup for Microsoft Azure backup appliance by checking the Backup Infrastructure > Managed Servers list for any 'Microsoft Azure backup appliance' type entries.
A vulnerability that may allow an attacker to utilize Server-Side Request Forgery (SSRF) to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Affects Veeam Backup for Microsoft Azure 7.1.0.22 and all earlier versions.
Severity: High
CVSS v3.1 Score: 7.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: Discovered during internal testing.
This form is only for KB Feedback/Suggestions, if you need help with the software open a support case