Umbra Wiki cve cve/CVE-2023-45249
Back to wiki

CVE-2023-45249 — Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

provenance: imported · CVE: CVE-2023-45249

CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Acronis
Product Cyber Infrastructure (ACI)
Date added 2024-07-29
Due date 2024-08-19
Ransomware campaign use Unknown

Description

Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://security-advisory.acronis.com/advisories/SEC-6452; https://nvd.nist.gov/vuln/detail/CVE-2023-45249

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-45249
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog