Skip to main content

Critical vulnerability in Acronis Cyber Infrastructure (ACI) could be exploited to achieve remote code execution

Summary

Critical vulnerability in Acronis Cyber Infrastructure (ACI) could be exploited to achieve remote code execution

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Acronis has released an update for a critical vulnerability in multiple Acronis Cyber Infrastructure (ACI) build versions. Acronis ACI is a multi-tenant, hyper-converged infrastructure solution for cyber protection.

The vulnerability is tracked as CVE-2023-45249 and has a CVSS3 score of 9.8. A remote attacker could exploit this default password vulnerability to achieve remote code execution (RCE).

Remediation advice

Affected organisations are encouraged to review Acronis Security Advisory SEC-6452 and apply any relevant updates.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 29 July 2024 4:17 pm