PT-2024-7387 · Acronis · Acronis Cyber Protect
Published
2024-10-15
·
Updated
2025-02-04
·
CVE-2024-49388
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
Acronis Cyber Protect 16 versions before build 38690
Description:
The issue is related to sensitive information manipulation due to improper authorization. This can be exploited by an attacker to elevate their privileges. The vulnerability exists because of improper authorization, allowing a remote attacker to potentially expose data.
Recommendations:
For Acronis Cyber Protect 16 versions before build 38690, update to a version that includes the fix for this issue, specifically build 38690 or later. As a temporary workaround, consider restricting access to sensitive information and implementing additional authorization controls until the update can be applied.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acronis Cyber Protect