KEVIntel
9.8
CVSS
Critical

CVE-2023-45249

PUBLISHED

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build...

Exploited in the wild Remote Low complexity No user interaction
Vendor
Acronis
Product
Acronis Cyber Infrastructure
Published
Jul 24, 2024
EPSS

Description

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

windows cisa nuclei_scanner metasploit nessus_scanner

CVSS scores

CVSS v3.0 9.8 Critical

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2024-07-29 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jul 29, 2024

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

acronis_cyber_infra_cve_2023_45249

metasploit · Created Unknown

Metasploit module for CVE-2023-45249

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus

  • Detected by Metasploit

  • Detected by Nuclei