PT-2023-5315 · Acronis · Acronis Cloud Manager

Putsi

·

Published

2023-08-31

·

Updated

2024-09-18

·

CVE-2023-41747

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Acronis Cloud Manager (Windows) versions before 6.2.23089.203
Description The issue is related to sensitive information disclosure due to unauthenticated path traversal and improper input validation. This allows a remote attacker to access confidential information.
Recommendations For versions before 6.2.23089.203, update to a version 6.2.23089.203 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until a patch is applied.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-05941
CVE-2023-41747

Affected Products

Acronis Cloud Manager