PT-2022-21987 · Acronis · Acronis Agent+3
Boldglum
+1
·
Published
2022-11-17
·
Updated
2025-10-07
·
CVE-2022-3405
CVSS v3.1
9.3
Critical
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Acronis Cyber Protect 15 versions prior to build 29486
Acronis Cyber Backup 12.5 versions prior to build 16545
Description
The issue is related to excessive privileges assigned to Acronis Agent, leading to code execution and sensitive information disclosure.
Recommendations
For Acronis Cyber Protect 15 versions prior to build 29486, update to build 29486 or later.
For Acronis Cyber Backup 12.5 versions prior to build 16545, update to build 16545 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acronis
Acronis Agent
Acronis Cyber Backup 12.5
Acronis Cyber Protect 15