PT-2024-7387 · Acronis · Acronis Cyber Protect

Published

2024-10-15

·

Updated

2025-02-04

·

CVE-2024-49388

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Acronis Cyber Protect 16 versions before build 38690
Description: The issue is related to sensitive information manipulation due to improper authorization. This can be exploited by an attacker to elevate their privileges. The vulnerability exists because of improper authorization, allowing a remote attacker to potentially expose data.
Recommendations: For Acronis Cyber Protect 16 versions before build 38690, update to a version that includes the fix for this issue, specifically build 38690 or later. As a temporary workaround, consider restricting access to sensitive information and implementing additional authorization controls until the update can be applied.

Fix

IDOR

Weakness Enumeration

Related Identifiers

BDU:2024-08756
CVE-2024-49388

Affected Products

Acronis Cyber Protect