First published: Wed Jun 21 2017(Updated: )
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis True Image | <=2017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3219 has a moderate severity as it allows potential attackers to manipulate software updates.
To fix CVE-2017-3219, upgrade Acronis True Image to a version after 2017 Build 8053.
Acronis True Image versions up to and including 2017 Build 8053 are affected by CVE-2017-3219.
CVE-2017-3219 is a software update verification vulnerability that uses an insecure MD5 hash.
The risks associated with CVE-2017-3219 include potential exploitation by attackers to provide malicious software updates.