Summary
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file.
Assessment
- CVE:
CVE-2025-55125 - CVSS base score: 7.8
- Vector:
CVSS:3.1\/AV:L\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H - Source: [NVD record](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-55125)
References
- [www.veeam.com](https:\/\/www.veeam.com\/kb4792)
Actions
- Verify affected systems in your inventory
- Apply the vendor patch during a maintenance window
- Restrict network-layer access until the patch is applied
veeam backup \& replication *