Impact
The vulnerability causes the guest operating system to write privileged account credentials in cleartext to a support log file. An attacker who can read that log can recover usernames and passwords, which can lead to further compromise. The weakness is an information exposure flaw that violates confidentiality.
Affected Systems
The affected product is Veeam Backup and Replication. No specific version details were supplied, so the risk applies to any installation that logs credentials to support logs.
Risk and Exploitability
The CVSS score is 6.8, indicating a moderate severity. The EPSS score is not available, so exploitation likelihood is currently unknown; the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve local or privileged users with read access to the support log, or attackers who gain such access after compromising the host.
OpenCVE Enrichment