Junglewise Threat Intelligence

CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

CVE-2023-45249 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-07-29

Vendors: Acronis.

Executive brief

Acronis Cyber Infrastructure (ACI) is vulnerable to remote command execution due to the use of insecure default passwords. An unauthenticated remote attacker can exploit this to gain full control over the affected system.

Affected products

  • Acronis Cyber Infrastructure (ACI) before build 5.0.1-61
  • Acronis Cyber Infrastructure (ACI) before build 5.1.1-71
  • Acronis Cyber Infrastructure (ACI) before build 5.2.1-69
  • Acronis Cyber Infrastructure (ACI) before build 5.3.1-53
  • Acronis Cyber Infrastructure (ACI) before build 5.4.4-132

Timeline

  • 2024-07-24: disclosed: NVD Published Date
  • 2024-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-29: exploited: Reported as exploited in the wild