CVE-2024-49382: Medium severity acronis cyber protect vulnerability
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49382?
CVE-2024-49382 has been classified with a critical severity rating due to the excessive attack surface it creates.
How do I fix CVE-2024-49382?
To mitigate CVE-2024-49382, ensure that the Acronis Cyber Protect service is configured to bind only to specific, restricted IP addresses.
What products are affected by CVE-2024-49382?
CVE-2024-49382 affects Acronis Cyber Protect 16 on both Linux and Windows platforms prior to build 38690.
When was CVE-2024-49382 disclosed?
CVE-2024-49382 was disclosed in 2024, highlighting issues in the archive-server service.
Is there any workaround for CVE-2024-49382?
Currently, the best workaround for CVE-2024-49382 is to restrict the binding of the affected service to specific IP addresses until an update is applied.