CVE-2022-3405: critical vulnerability in Acronis Cyber Protect 15
Published · Updated
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.3epss 5.3%
from disclosure to weapon0 days
Published on NVDMay 3
metasploitNov 8
exploitation probability
5.3%top 8% of all CVEs
observed exploitation
nono source reports it
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Related CVEs — Acronis Cyber Protect 15
In the same product, most dangerous first.
CVE-2022-30995CRITICALCVE-2022-30995EPSS 3.3%CVE-2023-44155MEDIUMCVE-2023-44155EPSS 1.1%CVE-2023-44156MEDIUMCVE-2023-44156EPSS 1.0%CVE-2023-44206HIGHCVE-2023-44206EPSS 1.0%CVE-2022-30990—Sensitive information disclosure due to insecure folder permissionsEPSS 0.9%CVE-2023-44152MEDIUMCVE-2023-44152EPSS 0.9%