Veeam has issued urgent patches to address critical vulnerabilities in its Veeam ONE monitoring platform. The identified vulnerability (CVE-2023-38547) exposes a significant security loophole, potentially allowing an attacker to execute code remotely on the SQL server.
Security Risks Escalate with NTLM Hash Exposure in Web Client
Adding to the urgency, Veeam disclosed another critical vulnerability (CVE-2023-38548) that exposes the Microsoft NTLM hash. This vulnerability, which resides in the Veeam ONE Web client, enables an unprivileged user to access sensitive information, emphasizing the need for immediate action to mitigate potential risks.
Veeam ONE versions 11, 11a, and 12, widely used across disaster recovery orchestrators (versions 5 and 6) and availability orchestrator (version 4), are affected. The severity of these vulnerabilities is reflected in the CVSS scores of 9.9 and 9.8, respectively.
Additional Concerns Addressed:
In addition to the critical vulnerabilities, Veeam has also tackled two lower-rated issues:
CVE-2023-38549 (CVSS score 4.5): This vulnerability, rated lower due to its exploitability only by a Veeam ONE Power User, could potentially lead to unauthorized access through a cross-site scripting (XSS) attack.
CVE-2023-41723 (CVSS score 4.3): Targeting those with read-only privileges, this vulnerability allowed users to view the software’s dashboard schedule.
Veeam emphasized that vulnerability testing was conducted exclusively on currently supported software versions. To implement the patches, users are required to apply hotfix files, necessitating the temporary shutdown and restart of Veeam ONE monitoring and reporting services. Users are strongly urged to expedite this patching process to safeguard their systems against potential security threats.

