Vulnerabilidades en Acronis

193 resultados
Análisis Vexday

Com 192 CVEs catalogadas, o portfólio de vulnerabilidades da Acronis apresenta uma taxa de exploração ativa acima da média geral do catálogo CISA KEV — proporção 1,2 vezes superior ao índice de referência —, o que indica atenção redobrada para equipes de resposta a incidentes. A CVE mais crítica em exploração confirmada é a CVE-2023-45249, com score EPSS de 0,5354, sugerindo probabilidade relevante de tentativas de exploração observadas em ambiente real. O tipo de falha mais recorrente é CWE-427 (uncontrolled search path element), classe que frequentemente permite escalonamento de privilégios ou execução de código por meio de dependências mal controladas. As 11 CVEs surgidas nos últimos 90 dias e as 8 de severidade crítica reforçam a necessidade de ciclos de patching ágeis para produtos Acronis em ambientes corporativos.

CVE-2022-30697Local privilege escalation due to insecure folder permissionsEPSS 0.2%CVE-2023-44157LOWLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) beforEPSS 0.2%CVE-2024-49392MEDIUMStored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (WinEPSS 0.2%CVE-2024-49384LOWExcessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: AcroniEPSS 0.2%CVE-2024-49382LOWExcessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: AcroniEPSS 0.2%CVE-2024-49383LOWExcessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: AcronisEPSS 0.2%CVE-2023-45247HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2023-45244HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2023-45246HIGHSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2022-24113Local privilege escalation due to excessive permissions assigned to child processesEPSS 0.2%CVE-2023-48676LOWSensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect CEPSS 0.2%CVE-2025-30409MEDIUMDenial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (WinEPSS 0.2%CVE-2024-34015LOWSensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis BEPSS 0.2%CVE-2024-34010HIGHLocal privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber Protect Cloud AgentEPSS 0.2%CVE-2022-44733HIGHLocal privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (WindoEPSS 0.2%CVE-2023-41745MEDIUMSensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (LinuEPSS 0.2%CVE-2023-45243MEDIUMSensitive information disclosure due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (LinuxEPSS 0.2%CVE-2022-0483Local privilege escalation due to insecure folder permissionsEPSS 0.2%CVE-2024-34014MEDIUMArbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin EPSS 0.2%CVE-2021-44204Local privilege escalation via named pipe due to improper access control checksEPSS 0.2%