ZeroHour
Security Affairspublished ()ingested @securityaffairs

Acronis Cyber Infrastructure bug actively exploited in the wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-45249

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-45249
Default-Password Remote Command Execution in Acronis Cyber Infrastructure

CVE-2023-45249 is an insecure default password flaw (CWE-1393) in Acronis Cyber Infrastructure (ACI) that allows unauthenticated remote command execution with a CVSS 3.1 score of 9.8. An attacker who can reach the exposed service over the network can authenticate with credentials left at vendor defaults and run arbitrary commands, gaining full confidentiality, integrity, and availability impact on the host. Organizations running ACI 5.0, 5.1, 5.2, 5.3, or 5.4 on builds earlier than the fixed builds are affected, particularly deployments where the ACI management interface is internet-facing. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-29 and multiple security outlets reported in-the-wild exploitation, with an EPSS of 53.3% (99th percentile). No public proof-of-concept is known, but exploitation activity has been observed directly.

Do: Upgrade each affected ACI deployment to the fixed build for its branch: at least 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, or 5.4.4-132 respectively. Immediately change any account or service passwords still set to vendor defaults, and restrict internet exposure of the ACI management interface. Per CISA's KEV required action, apply vendor mitigations (or discontinue use if unavailable), and review logs for signs of unauthorized access or command execution.

9.853% KEV
  • Acronis Cyber Infrastructure (ACI) all builds before 5.0.1-61
  • Acronis Cyber Infrastructure (ACI) all builds before 5.1.1-71
  • Acronis Cyber Infrastructure (ACI) all builds before 5.2.1-69
  • +2 more
moderateon the order of 1,000-10,000 exposed ACI instances (estimate)
Full article323 words · extracted from securityaffairs.com · click to collapse

Acronis warns of a critical vulnerability in its Acronis Cyber Infrastructure (ACI) solution that is being actively exploited in the wild.

Acronis is warning of a critical vulnerability, tracked as CVE-2023-45249 (CVSS score of 9.8), in its Acronis Cyber Infrastructure (ACI) solution that is being actively exploited in the wild.

ACI is a comprehensive IT solution designed to provide cyber protection and data management. It combines several key functionalities, including software-defined storage, software-defined networking, and advanced monitoring and management tools.

The company addressed the vulnerability at the end of 2023. Remote attackers can exploit the vulnerability to execute arbitrary code, the issue is due to the use of default passwords.

Affected products include:

  • Acronis Cyber Infrastructure (ACI) before build 5.4.4-132
  • Acronis Cyber Infrastructure (ACI) before build 5.0.1-61
  • Acronis Cyber Infrastructure (ACI) before build 5.1.1-71
  • Acronis Cyber Infrastructure (ACI) before build 5.2.1-69
  • Acronis Cyber Infrastructure (ACI) before build 5.3.1-53

The company addressed the vulnerability with the release of ACI versions 5.4 update 4.2, 5.2 update 1.3, 5.3 update 1.3, 5.0 update 1.4, and 5.1 update 1.2. The company urges customers to patch the issue as soon as possible.

“This update contains fixes for 1 ctitical severity security vulnerability and should be installed immediately by all users.” reads the advisory published by the company. “This vulnerability is known to be exploited in the wild.”

Experts have issued a warning that attacks targeting ACI can pose significant risks to enterprises that depend on this solution. The exploitation of vulnerabilities in ACI could lead to serious issues, including data breaches, disruption of services, and potential financial losses. The critical nature of these vulnerabilities underscores the importance of timely updates and robust security measures for enterprises using ACI to safeguard their data and infrastructure.

The experts warn that attacks against ACI can cause severe problems to enterprises that rely on this solution.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, ACI)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166277/hacking/acronis-cyber-infrastructure-bug-exploited.html