CVE-2023-44158: High severity acronis cyber protect vulnerability
Published Sep 27, 2023
·Updated
Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Affected Software
9 affected components
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Acronis Cyber Protect=15-update3
Acronis Cyber Protect=15-update4
Acronis Cyber Protect=15-update5
Linux Linux kernel
Microsoft Windows
Event History
Sep 27, 2023
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-44158?
CVE-2023-44158 is a vulnerability that results in sensitive information disclosure due to insufficient token field masking.
2
Which products are affected by CVE-2023-44158?
The following products are affected by CVE-2023-44158: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
3
What is the severity of CVE-2023-44158?
The severity of CVE-2023-44158 is high with a severity score of 7.5.
4
How can I fix CVE-2023-44158?
To fix CVE-2023-44158, update Acronis Cyber Protect 15 to build 35979 or later.
5
Where can I find more information about CVE-2023-44158?
More information about CVE-2023-44158 can be found at https://security-advisory.acronis.com/advisories/SEC-4071.