Description
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.
Published: 2023-11-07
Score: 5.4 Medium
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-42348 A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-09-04T18:52:45.750Z

Reserved: 2023-07-20T01:00:12.444Z

Link: CVE-2023-38549

cve-icon Vulnrichment

Updated: 2024-08-02T17:46:56.240Z

cve-icon NVD

Status : Modified

Published: 2023-11-07T07:15:09.187

Modified: 2024-11-21T08:13:48.593

Link: CVE-2023-38549

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses