Veeam ONE [1] [2] [3] [4] [5] [6] [7] [8], an IT infrastructure monitoring and analytics platform [1] [2] [7], has released hotfixes to address vulnerabilities in its system [2] [5]. These vulnerabilities include critical issues with a high severity rating.

Description

Veeam ONE has identified two critical vulnerabilities, CVE-2023-38547 and CVE-2023-38548 [1] [2] [3] [5] [6] [8], both rated 9.9 on the CVSS v3.1 scale [4]. CVE-2023-38547 allows an unauthenticated attacker to gain information about the SQL server connection used by Veeam ONE [2] [5] [6] [7] [8], potentially leading to remote code execution on the SQL server hosting the Veeam ONE configuration database [4] [7]. This vulnerability has been fixed in Veeam ONE 12 P20230314 (12.0.1.2591). CVE-2023-38548 allows an unprivileged user with access to the Veeam ONE Web Client to obtain the NTLM hash of the account used by the Veeam ONE Reporting Service [2] [3] [5] [7]. This vulnerability only affects Veeam ONE 12.

In addition to the critical vulnerabilities, Veeam ONE has also addressed two medium-severity vulnerabilities [1]. CVE-2023-38549 requires a user to interact with the product’s administrator role to obtain an access token [5]. CVE-2023-41723 allows a user with read-only access to view the Dashboard Schedule [5].

Conclusion

To ensure the security of their systems, users are advised to install the hotfixes provided by Veeam. These fixes address critical vulnerabilities that could lead to remote code execution and unauthorized access. By promptly applying the hotfixes, users can mitigate the risks associated with these vulnerabilities and protect their IT infrastructure.

References

[1] https://allinfosecnews.com/item/veeam-fixed-multiple-flaws-in-veeam-one-including-critical-issues-2023-11-07/
[2] https://sra.io/blog/critical-bugs-in-veeam-one-monitoring-platform/
[3] https://digital.nhs.uk/cyber-alerts/2023/cc-4405
[4] https://www.veeam.com/kb4508
[5] https://www.infosecurity-magazine.com/news/veeam-patches-two-critical-bugs/
[6] https://thehackernews.com/2023/11/critical-flaws-discovered-in-veeam-one.html
[7] https://vulnera.com/newswire/veeam-addresses-multiple-vulnerabilities-in-veeam-one-platform/
[8] https://www.csa.gov.sg/alerts-advisories/alerts/2023/al-2023-143