CVE-2023-45249
Description
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
Summary dbcve.org
Acronis Cyber Infrastructure ships with default administrative passwords that are never changed during installation. Attackers can authenticate to these default accounts over the network and execute arbitrary commands on the underlying operating system with elevated privileges.
Mitigation
Immediately change all default passwords to strong, unique values and upgrade to one of the fixed builds (5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, or 5.4.4-132) per the version ladder. Conduct a forensic review to determine if the system has been compromised.