First published: Mon Feb 22 2021(Updated: )
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis Cyber Protect | <15 | |
Acronis Cyber Protect | =15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35556
The affected software is Acronis Cyber Protect before 15 Update 1 build 26172.
The severity of CVE-2020-35556 is high with a CVSS score of 7.5.
CVE-2020-35556 can lead to information disclosure due to misconfigured CORS (Cross-Origin Resource Sharing) in the local notification service.
To mitigate CVE-2020-35556, it is recommended to update Acronis Cyber Protect to version 15 Update 1 build 26172 or later.