Sensitive Information Disclosure in Acronis Agent and Cyber Protect Products
CVE-2022-45459

3.8LOW

Key Information:

Vendor
Acronis
Vendor
CVE Published:
18 May 2023

Summary

This vulnerability arises from insecure registry permissions in Acronis Agent and Acronis Cyber Protect, potentially allowing unauthorized access to sensitive information. Affected users running versions prior to build 30025 for Acronis Agent and build 30984 for Acronis Cyber Protect on Windows may face significant security risks. It is crucial to apply the necessary updates to mitigate this exposure.

Affected Version(s)

Acronis Agent Windows < 30025

Acronis Cyber Protect 15 Windows < 30984

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.