CVE-2023-38547 is a critical vulnerability in Veeam ONE that allows an unauthenticated attacker to gain information about the SQL server connection used by the software. This could lead to remote code execution on the SQL server hosting the Veeam ONE configuration database. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community attention and media coverage, suggesting a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.0.1379CPE matchmatch criteria | cpe:2.3:a:veeam:one:11.0.0.1379:*:*:*:*:*:*:* | ||
11.0.1.1880CPE matchmatch criteria | cpe:2.3:a:veeam:one:11.0.1.1880:*:*:*:*:*:*:* | ||
12.0.0.2498CPE matchmatch criteria | cpe:2.3:a:veeam:one:12.0.0.2498:*:*:*:*:*:*:* | ||
12.0.1.2591CPE matchmatch criteria | cpe:2.3:a:veeam:one:12.0.1.2591:*:*:*:*:*:*:* | ||
>= 11, <= 11CPE match | cpe:2.3:a:veeam:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.