← All CVEs

CVE-2023-38547

critical · 9.8

A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database.

9.8
CVSS
18.9%
EPSS (exploit prob.)
97th
EPSS percentile
2023-11-07
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
veeamone11.0.0.1379
veeamone11.0.1.1880
veeamone12.0.0.2498
veeamone12.0.1.2591

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-38547