« Back to list

Acronis

Acronis Cyber Infrastructure: vulnerabilities and CVEs

Acronis Cyber Infrastructure has 3 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-45249Critical (9.8)53%⚠ Active exploitationJul 24, 2024
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-45249Critical (9.8)53%⚠ Active exploitationJul 24, 2024
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis…
CVE-2023-2782Medium (5.5)0.17%—May 18, 2023
Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.
CVE-2023-2360High (7.5)0.39%—Apr 28, 2023
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Acronis