Session Invalidation Flaw in Acronis Cyber Protect 16 by Acronis
CVE-2024-56413

Currently unrated

Key Information:

Vendor
Acronis
Vendor
CVE Published:
2 January 2025

Summary

Acronis Cyber Protect 16 contains a vulnerability due to missing session invalidation after user deletion. This flaw potentially allows unauthorized access, which could be exploited by malicious actors to continue to use a session associated with a deleted user account, thereby compromising sensitive information and system integrity. Users of Acronis Cyber Protect 16 (Windows) prior to build 39169 should review their security measures and consider applying the latest updates to mitigate potential risks.

Affected Version(s)

Acronis Cyber Protect 16 Windows < 39169

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@strgt (https://hackerone.com/strgt)
.