« Volver al listado

CVE-2023-44156

Estado: ModificadaAlta (7.5)—

Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-44156",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-44156",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-23T17:31:06.746293Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@acronis.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.7,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.1
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@acronis.com",
      "affectedData": [
        {
          "vendor": "Acronis",
          "product": "Acronis Cyber Protect 15",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "35979",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-09-27T15:19:37.817",
  "references": [
    {
      "url": "https://security-advisory.acronis.com/advisories/SEC-5124",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@acronis.com"
    },
    {
      "url": "https://security-advisory.acronis.com/advisories/SEC-5124",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@acronis.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-359"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979."
    },
    {
      "lang": "es",
      "value": "Divulgación de información confidencial debido a spell-jacking. Los siguientes productos se ven afectados: Acronis Cyber Protect 15 (Linux, Windows) antes de la build 35979."
    }
  ],
  "lastModified": "2026-06-17T06:27:00.803",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "547972AF-7F43-4A6D-AFC7-5514DD9995A6",
              "versionEndExcluding": "15"
            },
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:15:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89899D10-1343-4276-919A-9C1DF2DB8B55"
            },
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:15:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A77B2499-B3A4-4278-BA0D-59AB59C60352"
            },
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:15:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAF6A576-C320-4550-B7F8-4FCAE82FB06A"
            },
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:15:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9740A956-D589-4846-8717-B6182EB65F8B"
            },
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:15:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AB8B19B-2B40-4F1B-AE24-1C43D362E4BC"
            },
            {
              "criteria": "cpe:2.3:a:acronis:cyber_protect:15:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69506F27-DEF8-4317-9E54-D79CA430AD4B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@acronis.com"
}