Impact
The vulnerability allows attackers to execute arbitrary code on the Veeam ONE agent host without authentication. This means a remote user can run any command with system privileges, leading to full compromise of the host and potentially the entire Veeam environment.
Affected Systems
Veeam ONE is the affected product. The data does not list specific versions, so all installations may be vulnerable until a pull from the vendor is applied.
Risk and Exploitability
The CVSS score is 10, indicating the highest severity. EPSS is not available and the issue is not listed in CISA KEV, but the lack of any mitigation does not lower the risk; a remote attacker only needs network reach to the agent to exploit this flaw. Given the extreme severity, it is likely to be targeted once known.
OpenCVE Enrichment