Sensitive Information Disclosure in Acronis Cyber Protect Products
CVE-2023-45247
7.1HIGH
Key Information:
- Vendor
- Acronis
- Vendor
- CVE Published:
- 9 October 2023
Summary
A vulnerability exists in Acronis Cyber Protect products that allows unauthorized access to sensitive information due to missing authorization checks. This exposure may lead to data manipulation, putting users at risk. The affected versions include Acronis Cyber Protect Cloud Agent prior to build 36497 and Acronis Cyber Protect 16 prior to build 39169. Users are urged to update their software to mitigate potential risks.
Affected Version(s)
Acronis Cyber Protect 16 Linux < 39169
Acronis Cyber Protect Cloud Agent Linux < 36497
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved