Impact
The vulnerability involves improper validation of the returnUrl parameter in the Forgot Password feature of Veeam Service Provider Console. An unauthenticated attacker can supply a malicious domain within this parameter, causing the generated password reset link to point to an attacker‑controlled host. When the legitimate user follows the email link, the reset code is sent to the attacker, enabling account takeover by the attacker without any additional authentication steps. This flaw directly impacts confidentiality, integrity, and availability of user accounts and is identified as CWE‑640.
Affected Systems
Veeam Service Provider Console is the sole affected product listed by the CNA. The specific versions impacted are not enumerated in the available data, so all releases of the console remain potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% shows a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through an email response mechanism where the user is tricked into clicking a reset link. An attacker can therefore exploit this weakness with little effort and no presence on the target network, assuming the reset link is delivered via standard email.
OpenCVE Enrichment