← Vulnerability feed

Vulnerability record · CVE-2020-15419 · published 28 July 2020

CVE-2020-15419: Veeam ONE Reporter XXE allows unauthenticated file disclosure

Veeam · One Firmware

Veeam ONE 10.0.0.750_20200415 contains an XML External Entity (XXE) flaw in the Reporter_ImportLicense class. Because the XML parser resolves external entity references, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. This lets an unauthenticated remote attacker read files on the host.

7.5 CVSS 3.1 High EPSS 60% · top 0.9% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score, v2 7.8
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Reporter_ImportLicense class. Due to the improper restriction of XML External Entity (XXE) references, a specially crafted document specifying a URI causes the XML parser to access the URI and embed the contents back into the XML document for further processing. An attacker can leverage this vulnerability to disclose file contents in the context of SYSTEM. Was ZDI-CAN-10710.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable SYSTEM-context file disclosure with a high EPSS score, though no KEV listing or known public exploit.

What it is

Veeam ONE 10.0.0.750_20200415 contains an XML External Entity (XXE) flaw in the Reporter_ImportLicense class. Because the XML parser resolves external entity references, a crafted document can make the parser fetch a URI and embed its contents into the processed XML. This lets an unauthenticated remote attacker read files on the host.

Impact

An attacker gains disclosure of file contents in the context of SYSTEM, meaning sensitive configuration, credential or system files on the Veeam ONE server can be read. There is no integrity or availability impact per the CVSS vector.

Attack surface

The flaw is network reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so an unauthenticated attacker who can reach the affected Veeam ONE service can submit the crafted XML document. No authentication is required per the description.

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is recorded in the references, but EPSS is high at 0.598 (99th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are only Vendor Advisory and Third Party Advisory/VDB Entry.

What to do

  • Apply the Veeam fix referenced in vendor advisory KB3221 for Veeam ONE 10.0.0.750_20200415.
  • Restrict network access to the Veeam ONE Reporter service to trusted management networks only.
  • Disable or block external entity and DTD resolution in XML parsers where configuration is exposed.
  • Monitor and alert on unexpected outbound requests from the Veeam ONE host to attacker-controlled URIs.
  • Review the host for signs of file exfiltration if the service was internet-exposed.

Detection

  • Inspect Veeam ONE Reporter logs for license import or XML parsing errors and unusual URI references.
  • Alert on outbound HTTP/S or file URI requests originating from the Veeam ONE server process.
  • Hunt for crafted XML payloads containing DOCTYPE or ENTITY declarations submitted to the Reporter_ImportLicense endpoint.
  • Correlate Veeam ONE service account or SYSTEM-level file reads with anomalous process behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15419 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-15418Veeam one firmware xml external entity (xxe) vulnerabilityThis vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…EPSS 9.4%9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed7.5CVE-2023-45727Proself XXE flaw allows unauthenticated file readProself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote…KEVEPSS 3.5%analysed9.8CVE-2024-34102Adobe Commerce and Magento XXE flaw allows unauthenticated code executionAdobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML do…KEVEPSS 100%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed7.5CVE-2019-13608Citrix StoreFront Server XXE allows unauthenticated file disclosureCitrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) is vulnerable to XML External Entity (XXE)…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2020-15419), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.