CVE-2023-38549
No sign of exploitation. No public exploitation artifact known so far.
An unprivileged user accessing Veeam ONE Web Client can steal the NTLM password hash of the Veeam ONE Reporting Service account. This allows attackers to potentially compromise the service account and gain unauthorized access to sensitive backup data.
The vulnerability enables NTLM hash extraction through the Veeam ONE Web Client interface accessible to unprivileged users. Exploitation requires network access to the web client and knowledge of the target service account; however, impact is mitigated by the requirement that an Administrator role user must interact with the malicious request. The compromised hash could be used in pass-the-hash attacks or offline cracking attempts.