CVE-2025-30413: Medium severity Acronis Acronis Cyber Protect Cloud Agent vulnerability
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30413?
CVE-2025-30413 is considered a moderate severity vulnerability due to the potential exposure of credentials after plan revocation.
How do I fix CVE-2025-30413?
You can fix CVE-2025-30413 by updating the Acronis Cyber Protect Cloud Agent to build 40497 or Acronis Cyber Protect 17 to build 41186 or later.
Which products are affected by CVE-2025-30413?
CVE-2025-30413 affects Acronis Cyber Protect Cloud Agent and Acronis Cyber Protect 17 before the specified builds.
What consequences could arise from CVE-2025-30413?
If CVE-2025-30413 is exploited, it may lead to unauthorized access to sensitive credentials that were not deleted after plan revocation.
Is there a workaround for CVE-2025-30413 until I can update?
Currently, there is no specified workaround for CVE-2025-30413, so updating to the latest builds is recommended.