← Back

CVE-2022-3405

nvd nist
Published: May 3, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.

Affected (19)

2 products
Cyber Backup
Cyber Protect
Configuration A
19 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Acronis
Version 12.5
Version 12.5 10130
Version 12.5 10330
Version 12.5 11010
Version 12.5 13160
Version 12.5 13400
Version 12.5 14280
Version 12.5 14330
Version 12.5 16180
Version 12.5 16318
Version 12.5 16327
Version 12.5 7641
Version 12.5 7970
Version 12.5 8850
Version 12.5 9010
Acronis
Version 15
Version 15 update1
Version 15 update2
Version 15 update3
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (4)

Source: security@acronis.com
ExploitThird Party Advisory
Source: security@acronis.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.