CVE-2024-55539: Low severity acronis cyber protect cloud agent (linux) vulnerability
Published Dec 23, 2024
·Updated
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185, Acronis Cyber Protect 16 (Linux) before build 39938.
Affected Software
2 affected components
Acronis Cyber Protect Cloud Agent (Linux)<39185
Acronis Cyber Protect 16 (Linux)<39938
Event History
Dec 23, 2024
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-55539?
The severity of CVE-2024-55539 is categorized as high due to the weak algorithm used to sign RPM packages.
2
How do I fix CVE-2024-55539?
To fix CVE-2024-55539, update the Acronis Cyber Protect Cloud Agent to build 39185 or later.
3
Which products are affected by CVE-2024-55539?
CVE-2024-55539 affects Acronis Cyber Protect Cloud Agent (Linux) versions prior to build 39185.
4
What consequences does CVE-2024-55539 pose?
CVE-2024-55539 may allow attackers to manipulate RPM packages due to the use of a weak signing algorithm.
5
Is there a workaround for CVE-2024-55539?
No official workaround for CVE-2024-55539 has been provided, so the recommended action is to complete the update.