Remote Command Execution Vulnerability in Acronis Cloud Manager for Windows
CVE-2023-41746

8HIGH

Key Information:

Vendor
Acronis
Vendor
CVE Published:
31 August 2023

Summary

A vulnerability has been identified in Acronis Cloud Manager for Windows, attributed to improper input validation, which could allow remote command execution by an attacker. Users are advised to update to build 6.2.23089.203 or later to mitigate risks. For comprehensive information, refer to the vendor advisory.

Affected Version(s)

Acronis Cloud Manager Windows < 6.2.23089.203

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@putsi (https://hackerone.com/putsi)
.