CVE-2022-3405: Critical severity acronis backup vulnerability
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3405?
CVE-2022-3405 is a vulnerability that allows code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent.
Which products are affected by CVE-2022-3405?
The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
How severe is CVE-2022-3405?
CVE-2022-3405 has a severity rating of 8.8 (critical).
How do I fix CVE-2022-3405?
To fix CVE-2022-3405, upgrade to Acronis Cyber Protect 15 build 29486 or later, or Acronis Cyber Backup 12.5 build 16545 or later.
Are Linux and Microsoft Windows vulnerable to CVE-2022-3405?
No, Linux and Microsoft Windows are not vulnerable to CVE-2022-3405.