{"dataType": "CVE_RECORD", "containers": {"cna": {"metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "CHANGED", "version": "3.1", "baseScore": 9.9, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}}], "affected": [{"cpes": ["cpe:2.3:a:veeam:veeam_backup_\\&_replication:*:*:*:*:*:*:*:*"], "vendor": "veeam", "product": "veeam_backup_\\&_replication", "versions": [{"status": "affected", "version": "12.0.0.1402", "lessThan": "12.3.2.4165", "versionType": "custom"}], "defaultStatus": "unaffected"}], "references": [{"url": "https://www.veeam.com/kb4771", "tags": ["vendor-advisory"]}], "descriptions": [{"lang": "en", "value": "A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the Backup infrastructure hosts by an authenticated domain user."}], "problemTypes": [{"descriptions": [{"lang": "en", "cweId": "CWE-284", "description": "CWE-284"}, {"lang": "en", "description": "NVD-CWE-noinfo"}]}], "providerMetadata": {"orgId": "00000000-0000-4000-A000-000000000003", "shortName": "nvd", "dateUpdated": "2025-10-31T00:15:36Z", "x_subShortName": "nvd"}}}, "cveMetadata": {"cveId": "CVE-2025-48983", "state": "PUBLISHED", "dateUpdated": "2025-12-01T21:15:50Z", "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1", "datePublished": "2025-10-31T00:15:36Z", "assignerShortName": "hackerone"}, "dataVersion": "5.0"}