10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user.
AI Analysis
Remote code execution vulnerability in Veeam Backup and Replication Mount service
Basic Information
ID
CVE-2025-48983
Source
hackerone
Published
Oct 30, 2025 at 23:33
Affected Product
Vendor
Veeam
Product
Backup and Replication
Version
12.3.2
Affected Versions
Veeam Backup and Replication 12.3.2
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Veeam
Product
Veeam Backup and Replication
Version
12.3.2