Executive brief
Acronis Cyber Infrastructure (ACI) is vulnerable to remote command execution due to the use of insecure default passwords. An unauthenticated remote attacker can exploit this to gain full control over the affected system.
Affected products
- Acronis Cyber Infrastructure (ACI) before build 5.0.1-61
- Acronis Cyber Infrastructure (ACI) before build 5.1.1-71
- Acronis Cyber Infrastructure (ACI) before build 5.2.1-69
- Acronis Cyber Infrastructure (ACI) before build 5.3.1-53
- Acronis Cyber Infrastructure (ACI) before build 5.4.4-132
Timeline
- 2024-07-24: disclosed: NVD Published Date
- 2024-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-29: exploited: Reported as exploited in the wild