First published: Thu Dec 14 2023(Updated: )
Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36943.
Credit: security@acronis.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Acronis Cyber Protect Cloud Agent | =21-update12 | |
Acronis Cyber Protect Cloud Agent | =21-update3 | |
Acronis Cyber Protect Cloud Agent | =21-update6 | |
Acronis Cyber Protect Cloud Agent | =21-update7 | |
Acronis Cyber Protect Cloud Agent | =22-update10 | |
Acronis Cyber Protect Cloud Agent | =22-update11 | |
Acronis Cyber Protect Cloud Agent | =22-update2 | |
Acronis Cyber Protect Cloud Agent | =22-update3 | |
Acronis Cyber Protect Cloud Agent | =22-update5 | |
Acronis Cyber Protect Cloud Agent | =22-update7 | |
Acronis Cyber Protect Cloud Agent | =22-update8 | |
Acronis Cyber Protect Cloud Agent | =22-update9 | |
Acronis Cyber Protect Cloud Agent | =23-uddate1 | |
Acronis Cyber Protect Cloud Agent | =23-update10 | |
Acronis Cyber Protect Cloud Agent | =23-update11 | |
Acronis Cyber Protect Cloud Agent | =23-update12 | |
Acronis Cyber Protect Cloud Agent | =23-update2 | |
Acronis Cyber Protect Cloud Agent | =23-update3 | |
Acronis Cyber Protect Cloud Agent | =23-update5 | |
Acronis Cyber Protect Cloud Agent | =23-update6 | |
Acronis Cyber Protect Cloud Agent | =23-update7 | |
Acronis Cyber Protect Cloud Agent | =23-update8 | |
Acronis Cyber Protect Cloud Agent | =23-update9 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-48676 is categorized as high due to sensitive information disclosure and manipulation risks.
To fix CVE-2023-48676, upgrade Acronis Cyber Protect Cloud Agent to build 36943 or later.
CVE-2023-48676 affects Acronis Cyber Protect Cloud Agent versions 21-update3, 21-update6, 21-update7, 22-update2 to 22-update11, and 23-update1 to 23-update12.
CVE-2023-48676 is a vulnerability related to missing authorization, leading to sensitive information disclosure.
No, Microsoft Windows itself is not vulnerable, but the Acronis Cyber Protect Cloud Agent running on it may be.