PT-2023-5778 · Acronis · Acronis Cyber Protect 15+1

Laz0Rde

·

Published

2023-09-27

·

Updated

2023-09-28

·

CVE-2023-44161

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Acronis Cyber Protect 15 versions before build 35979
Description The issue is related to sensitive information manipulation due to cross-site request forgery, which can be exploited by a remote attacker to impact the integrity of protected information. This is caused by insufficient authentication of executed requests.
Recommendations For Acronis Cyber Protect 15 versions before build 35979, update to a version after build 35979 to resolve the issue. As a temporary workaround, consider implementing additional authentication measures for requests to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06464
CVE-2023-44161

Affected Products

Acronis
Acronis Cyber Protect 15