CVE-2023-38549 is a vulnerability in Veeam ONE that allows an unprivileged user with access to the Veeam ONE Web Client to obtain the NTLM hash of the Veeam ONE Reporting Service account. This medium-severity vulnerability has a CVSS score of 5.4, requiring user interaction from a Veeam ONE Administrator for exploitation, but could lead to limited confidentiality and integrity impact. While not currently listed in CISA KEV and lacking public exploit code, it has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0.0.1379CPE matchmatch criteria | cpe:2.3:a:veeam:one:11.0.0.1379:*:*:*:*:*:*:* | ||
11.0.1.1880CPE matchmatch criteria | cpe:2.3:a:veeam:one:11.0.1.1880:*:*:*:*:*:*:* | ||
12.0.0.2498CPE matchmatch criteria | cpe:2.3:a:veeam:one:12.0.0.2498:*:*:*:*:*:*:* | ||
12.0.1.2591CPE matchmatch criteria | cpe:2.3:a:veeam:one:12.0.1.2591:*:*:*:*:*:*:* | ||
>= 11, <= 11CPE match | cpe:2.3:a:veeam:one:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.