A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
References
History

Thu, 06 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-03-06T15:32:40.184Z

Reserved: 2023-07-20T01:00:12.444Z

Link: CVE-2023-38548

cve-icon Vulnrichment

Updated: 2024-08-02T17:46:55.720Z

cve-icon NVD

Status : Modified

Published: 2023-11-07T07:15:08.673

Modified: 2025-03-06T16:15:42.350

Link: CVE-2023-38548

cve-icon Redhat

No data.