Sensitive Information Disclosure Vulnerability in Acronis Cyber Protect Products
CVE-2023-45244
7.1HIGH
Key Information:
- Vendor
- Acronis
- Vendor
- CVE Published:
- 6 October 2023
Summary
A vulnerability exists within Acronis Cyber Protect products, allowing unauthorized access to sensitive information due to inadequate authorization checks. Specifically, this affects Acronis Cyber Protect Cloud Agent and Acronis Cyber Protect 16 across multiple operating systems prior to specific builds. Attackers could exploit this flaw to manipulate or access sensitive data without sufficient permissions, leading to potential data breaches.
Affected Version(s)
Acronis Cyber Protect 16 Linux < 37391
Acronis Cyber Protect Cloud Agent Linux < 35895
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved