← Back

CVE-2020-16171

nvd nist
Published: Sep 21, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.

Affected (16)

1 product
Cyber Backup
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 12.5
Configuration B
15 vulnerable
Vulnerable SoftwareAffected Versions
Acronis
Version 12.5
Version 12.5 10130
Version 12.5 10330
Version 12.5 11010
Version 12.5 13160
Version 12.5 13400
Version 12.5 14280
Version 12.5 14330
Version 12.5 16180
Version 12.5 16318
Version 12.5 16327
Version 12.5 7641
Version 12.5 7970
Version 12.5 8850
Version 12.5 9010

References (4)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory

Timeline

No history available yet.