CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
Other sources
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Acronis Cyber Infrastructure (ACI)to a version that resolves this vulnerability.Fixed in 5.0.1-61 - Upgrade
Upgrade
Acronis Cyber Infrastructure (ACI)to a version that resolves this vulnerability.Fixed in 5.1.1-71 - Upgrade
Upgrade
Acronis Cyber Infrastructure (ACI)to a version that resolves this vulnerability.Fixed in 5.2.1-69 - Upgrade
Upgrade
Acronis Cyber Infrastructure (ACI)to a version that resolves this vulnerability.Fixed in 5.3.1-53 - Upgrade
Upgrade
Acronis Cyber Infrastructure (ACI)to a version that resolves this vulnerability.Fixed in 5.4.4-132 - Remove
Remove
Acronis Cyber Infrastructure (ACI)from your environment.Discontinue use or uninstall the product if vendor mitigations are unavailable.
- Compensating control
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45249?
CVE-2023-45249 has been classified as a critical vulnerability due to its potential for remote command execution by unauthenticated users.
How do I fix CVE-2023-45249?
To mitigate CVE-2023-45249, it is essential to change all default passwords on affected Acronis Cyber Infrastructure systems.
Which versions of Acronis Cyber Infrastructure are affected by CVE-2023-45249?
CVE-2023-45249 affects Acronis Cyber Infrastructure versions prior to build 5.0.1-61 and all versions up to 5.4.4-132.
What kind of attack does CVE-2023-45249 enable?
CVE-2023-45249 allows attackers to execute arbitrary commands remotely due to the use of default passwords.
Is there a patch available for CVE-2023-45249?
Yes, Acronis has released a patch for CVE-2023-45249, which users should apply immediately to secure their systems.