CVE-2023-38549: Veeam One
Medium severity, CVSS 5.4. EPSS: 19.1% chance of exploitation in the next 30 days.
A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service. Note: The criticality of this vulnerability is reduced as it requires interaction by a user with the Veeam ONE Administrator role.
Affected products
- Veeam One: version 11.0.0.1379 only; version 11.0.1.1880 only; version 12.0.0.2498 only; version 12.0.1.2591 only
Published 2023-11-07. Last modified 2026-06-17.