CVE-2023-38547: critical vulnerability in Veeam One
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
An unauthenticated attacker can discover sensitive SQL server connection details used by Veeam ONE, potentially leading to remote code execution on the database server. This is critical because it exposes database credentials without requiring any login.
CWE-200 information disclosure vulnerability in Veeam ONE allows unauthenticated access to SQL server connection strings and credentials. An attacker can leverage this exposed information to authenticate to the underlying SQL database and achieve remote code execution through SQL injection or database-level exploits, bypassing application-level security controls.
In the same product, most dangerous first.