CVE-2023-38548: Veeam One

Medium severity, CVSS 4.3. EPSS: 11.8% chance of exploitation in the next 30 days.

A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.

Affected products

  • Veeam One: version 12.0.0.2498 only; version 12.0.1.2591 only

Published 2023-11-07. Last modified 2026-06-17.