Vulnerability record · CVE-2020-15419 · published 28 July 2020
CVE-2020-15419: Veeam ONE Reporter XXE allows unauthenticated file disclosure
Veeam · One Firmware
Veeam ONE 10.0.0.750_20200415 contains an XML External Entity (XXE) flaw in the Reporter_ImportLicense class. Because the XML parser resolves external entity references, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. This lets an unauthenticated remote attacker read files on the host.
Description
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10710.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable SYSTEM-context file disclosure with a high EPSS score, though no KEV listing or known public exploit.
What it is
Veeam ONE 10.0.0.750_20200415 contains an XML External Entity (XXE) flaw in the Reporter_ImportLicense class. Because the XML parser resolves external entity references, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. This lets an unauthenticated remote attacker read files on the host.
Impact
An attacker gains disclosure of file contents in the context of SYSTEM, meaning sensitive configuration, credential or system files on the Veeam ONE server can be read. There is no integrity or availability impact per the CVSS vector.
Attack surface
The flaw is network reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so an unauthenticated attacker who can reach the affected Veeam ONE service can submit the crafted XML document. No authentication is required per the description.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is recorded in the references, but EPSS is high at 0.598 (99th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are only Vendor Advisory and Third Party Advisory/VDB Entry.
What to do
- Apply the Veeam fix referenced in vendor advisory KB3221 for Veeam ONE 10.0.0.750_20200415.
- Restrict network access to the Veeam ONE Reporter service to trusted management networks only.
- Disable or block external entity and DTD resolution in XML parsers where configuration is exposed.
- Monitor and alert on unexpected outbound requests from the Veeam ONE host to attacker-controlled URIs.
- Review the host for signs of file exfiltration if the service was internet-exposed.
Detection
- Inspect Veeam ONE Reporter logs for license import or XML parsing errors and unusual URI references.
- Alert on outbound HTTP/S or file URI requests originating from the Veeam ONE server process.
- Hunt for crafted XML payloads containing DOCTYPE or ENTITY declarations submitted to the Reporter_ImportLicense endpoint.
- Correlate Veeam ONE service account or SYSTEM-level file reads with anomalous process behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.veeam.com/kb3221 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-822/ | Third Party AdvisoryVDB Entry |
| https://www.veeam.com/kb3221 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-20-822/ | Third Party AdvisoryVDB Entry |
Track CVE-2020-15419 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15419), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.