CVE-2024-34014: Medium severity acronis backup plugin for cpanel & whm (linux) vulnerability
Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34014?
CVE-2024-34014 is considered to have a critical severity due to the potential for arbitrary file overwrite.
How do I fix CVE-2024-34014?
To fix CVE-2024-34014, update Acronis Backup plugins and extensions to the latest builds: 818 for cPanel & WHM, 599 for Plesk, and 181 for DirectAdmin.
What products are affected by CVE-2024-34014?
CVE-2024-34014 affects Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for Plesk, and Acronis Backup plugin for DirectAdmin versions prior to specified builds.
What can happen if CVE-2024-34014 is exploited?
Exploitation of CVE-2024-34014 could allow attackers to overwrite arbitrary files on the affected systems.
Is there a workaround for CVE-2024-34014 if I can't update?
Currently, there are no known workarounds for CVE-2024-34014, so immediate updates are recommended.