CVE-2023-45249 — Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Acronis |
| Product | Cyber Infrastructure (ACI) |
| Date added | 2024-07-29 |
| Due date | 2024-08-19 |
| Ransomware campaign use | Unknown |
Description
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
Required action (CISA)
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://security-advisory.acronis.com/advisories/SEC-6452; https://nvd.nist.gov/vuln/detail/CVE-2023-45249
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-45249
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog