First published: Tue Nov 07 2023(Updated: )
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Veeam ONE | =12.0.0.2498 | |
Veeam ONE | =12.0.1.2591 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-38548.
The title of this vulnerability is 'A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client ...'
The severity of CVE-2023-38548 is critical with a severity value of 9.8.
The software affected by CVE-2023-38548 is Veeam ONE version 12.0.0.2498 and 12.0.1.2591.
To fix CVE-2023-38548, it is recommended to follow the instructions provided by Veeam in their knowledge base article: [link](https://www.veeam.com/kb4508).