CVE-2024-49384: Medium severity acronis cyber protect vulnerability
Published Oct 15, 2024
·Updated
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Affected Software
5 affected components
All of the following
Any of the following
Acronis Cyber Protect<=15
Acronis Cyber Protect=16
Acronis Cyber Protect=16-update1
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Oct 15, 2024
CVE Published
via MITRE·10:33 AM
Data Sourced
via MITRE·10:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49384?
CVE-2024-49384 is considered a high severity vulnerability due to its impact on the acep-collector service.
2
How do I fix CVE-2024-49384?
To fix CVE-2024-49384, upgrade Acronis Cyber Protect 16 to build 38690 or later.
3
Which products are affected by CVE-2024-49384?
CVE-2024-49384 affects Acronis Cyber Protect 16 for both Linux and Windows prior to build 38690.
4
What is the nature of the vulnerability in CVE-2024-49384?
CVE-2024-49384 involves an excessive attack surface due to the acep-collector service binding to an unrestricted IP address.
5
Are there any workarounds for CVE-2024-49384?
Currently, the recommended action for CVE-2024-49384 is to apply the appropriate software update, as no specific workarounds are provided.