Back to overview

CVE-2023-38547

CRITICAL
9.9
CVSS 3.0
Description
A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.

Metadata

CVE ID
CVE-2023-38547
State
PUBLISHED
Assigner
hackerone
Reserved
2023-07-20 01:00 UTC
Published
2023-11-07 06:17 UTC
Last updated
2025-03-06 15:33 UTC
Primary CWE
CWE-200
CWE-200 Exposure of Sensitive Information to an Unauthorized…
Vendor / Product
Veeam / One
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Veeam One 11 ≤ 11, 11a ≤ 11a, 12 ≤ 12
Weakness (CWE)
CWESourceDescription
CWE-200 adp CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview