Impact
A vulnerability in Veeam:One allows an unauthenticated network attacker to coerce SMB authentication from the service account, effectively bypassing authentication controls. The attacker can obtain privileged SMB credentials and thereby gain unauthorized access to files or services that rely on those credentials. The weakness is a classic authentication bypass (CWE‑288).
Affected Systems
Veeam:One products are affected; no specific version information is available in the advisory.
Risk and Exploitability
The CVSS score of 9.3 marks this a high‑severity flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based attack against SMB, requiring the target to expose an SMB interface controlled by Veeam:One. An attacker can trigger the coercion without prior authentication, making exploitation straightforward if the service is reachable.
OpenCVE Enrichment