CVE-2023-38549: XSS
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-38549?
CVE-2023-38549 is a vulnerability in Veeam ONE that allows an unprivileged user to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.
How does CVE-2023-38549 affect Veeam ONE?
CVE-2023-38549 affects Veeam ONE versions 11.0.0.1379, 11.0.1.1880, 12.0.0.2498, and 12.0.1.2591.
What is the severity of CVE-2023-38549?
CVE-2023-38549 has a severity score of 5.4 (medium).
How can I fix CVE-2023-38549?
To fix CVE-2023-38549, update Veeam ONE to the latest version available and follow the recommendations provided in the Veeam KB4508 article (link provided).
What is CWE-79?
CWE-79 is a Common Weakness Enumeration category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').