CVE-2023-45249 is a critical remote command execution vulnerability affecting multiple builds of Acronis Cyber Infrastructure (ACI) due to the use of default passwords. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary code remotely with high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, with public exploit code available via Metasploit and significant community discussion. Media outlets have also reported on its active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.1-61CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_infrastructure:*:*:*:*:*:*:*:* | ||
>= 5.1.1, < 5.1.1-71CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_infrastructure:*:*:*:*:*:*:*:* | ||
>= 5.2.1, < 5.2.1-69CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_infrastructure:*:*:*:*:*:*:*:* | ||
>= 5.3.1, < 5.3.1-53CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_infrastructure:*:*:*:*:*:*:*:* | ||
>= 5.4.4, < 5.4.4-132CPE matchmatch criteria | cpe:2.3:a:acronis:cyber_infrastructure:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.