← Back to browse · API

CVE-2023-38548

Severity
CRITICAL
CVSS
9.8
EPSS
0.11806
Risk score
43.33
CISA KEV
No
PoC
No
Published
2023-11-07
Modified
2025-03-06
First seen
2026-08-07
Aliases
EUVD-2023-42347, GHSA-5V7J-RMQQ-795G
Products
Samsung Open Source:One 12 ≤12
Sources
euvd EUVD-2023-42347

Description

A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service.

References