CVE-2023-45249
Acronis Cyber Infrastructure
Published 24 Jul 2024 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 29 Jul 2024, with a remediation deadline of 19 Aug 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
References
- security-advisory.acronis.com/advisories/SEC-6452 · Vendor Advisory
- www.securityweek.com/acronis-product-vulnerability-exploited-in-the-wild/ · Press/Media Coverage
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-45249 · Third Party Advisory, US Government Resource