ZeroHour

CVE-2023-45249

KEVmoderate1

Default-Password Remote Command Execution in Acronis Cyber Infrastructure

CISA: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

CVSS 3.1
9.8 critical
EPSS
53%p99
Published
()
KEV added
AI analysis

CVE-2023-45249 is an insecure default password flaw (CWE-1393) in Acronis Cyber Infrastructure (ACI) that allows unauthenticated remote command execution with a CVSS 3.1 score of 9.8. An attacker who can reach the exposed service over the network can authenticate with credentials left at vendor defaults and run arbitrary commands, gaining full confidentiality, integrity, and availability impact on the host. Organizations running ACI 5.0, 5.1, 5.2, 5.3, or 5.4 on builds earlier than the fixed builds are affected, particularly deployments where the ACI management interface is internet-facing. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-29 and multiple security outlets reported in-the-wild exploitation, with an EPSS of 53.3% (99th percentile). No public proof-of-concept is known, but exploitation activity has been observed directly.

What to do: Upgrade each affected ACI deployment to the fixed build for its branch: at least 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, or 5.4.4-132 respectively. Immediately change any account or service passwords still set to vendor defaults, and restrict internet exposure of the ACI management interface. Per CISA's KEV required action, apply vendor mitigations (or discontinue use if unavailable), and review logs for signs of unauthorized access or command execution.

Affected
Acronis Cyber Infrastructure (ACI)all builds before 5.0.1-61
Acronis Cyber Infrastructure (ACI)all builds before 5.1.1-71
Acronis Cyber Infrastructure (ACI)all builds before 5.2.1-69
Acronis Cyber Infrastructure (ACI)all builds before 5.3.1-53
Acronis Cyber Infrastructure (ACI)all builds before 5.4.4-132
Estimated exposure
moderateon the order of 1,000-10,000 exposed ACI instances (estimate) — ACI is niche data-center/hyperconverged infrastructure software typically deployed by service providers, MSPs, and enterprises rather than mass-market users, and its management interfaces are frequently left internet-exposed; no install or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

CISA Known Exploited Vulnerability
Affected
Acronis Cyber Infrastructure (ACI)
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
acronis
Products
cyber infrastructure
Weakness
CWE-1393
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news