CVE-2017-3219: High severity acronis true image vulnerability
Published Jun 21, 2017
·Updated
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
Affected Software
1 affected component
Acronis True Image<=2017
Event History
Jun 21, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3219?
CVE-2017-3219 has a moderate severity as it allows potential attackers to manipulate software updates.
2
How do I fix CVE-2017-3219?
To fix CVE-2017-3219, upgrade Acronis True Image to a version after 2017 Build 8053.
3
What versions of Acronis True Image are affected by CVE-2017-3219?
Acronis True Image versions up to and including 2017 Build 8053 are affected by CVE-2017-3219.
4
What type of vulnerability is CVE-2017-3219?
CVE-2017-3219 is a software update verification vulnerability that uses an insecure MD5 hash.
5
What risks are associated with CVE-2017-3219?
The risks associated with CVE-2017-3219 include potential exploitation by attackers to provide malicious software updates.