CRITICAL

CVE-2023-45249

Acronis Cyber Infrastructure 2024-07-24 CVSS v3.1
CVSS
9.8
KEV

Description

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

Summary dbcve.org

Acronis Cyber Infrastructure ships with default administrative passwords that are never changed during installation. Attackers can authenticate to these default accounts over the network and execute arbitrary commands on the underlying operating system with elevated privileges.

Mitigation

Immediately change all default passwords to strong, unique values and upgrade to one of the fixed builds (5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, or 5.4.4-132) per the version ladder. Conduct a forensic review to determine if the system has been compromised.

Weakness (CWE)

CWE-1393

EPSS Score

53.26%
Probability of exploitation in next 30 days
99th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE