📦 Cyber Protect

by Acronis

🔍 What is Cyber Protect?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-49388

CRITICAL CVSS 9.1 Oct 15, 2024

CVE-2024-49388 is an authorization bypass vulnerability in Acronis Cyber Protect 16 that allows attackers to manipulate sensitive information without proper authentication. This affects Acronis Cyber ...

CVE-2023-44206

CRITICAL CVSS 9.1 Sep 27, 2023

CVE-2023-44206 is an authorization bypass vulnerability in Acronis Cyber Protect 15 that allows attackers to access and manipulate sensitive information without proper authentication. This affects all...

CVE-2023-44152

CRITICAL CVSS 9.1 Sep 27, 2023

This vulnerability allows attackers to bypass authentication mechanisms in Acronis Cyber Protect 15, potentially leading to unauthorized access, sensitive information disclosure, and system manipulati...

CVE-2024-55543

HIGH CVSS 7.8 Jan 2, 2025

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 16 for Windows due to DLL hijacking. Attackers with local access can exploit this to execute arbitrary code with ...

CVE-2024-55540

HIGH CVSS 7.8 Jan 2, 2025

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 16 for Windows due to DLL hijacking. Attackers with local access can exploit this to execute arbitrary code with ...

CVE-2024-49387

HIGH CVSS 7.5 Oct 15, 2024

This vulnerability allows attackers to intercept sensitive information transmitted in cleartext by the acep-collector service in Acronis Cyber Protect 16. Organizations using affected versions on Linu...

CVE-2023-44154

HIGH CVSS 8.1 Sep 27, 2023

CVE-2023-44154 is an authorization bypass vulnerability in Acronis Cyber Protect 15 that allows unauthorized users to access and manipulate sensitive information. This affects Acronis Cyber Protect 15...

CVE-2023-44156

HIGH CVSS 7.5 Sep 27, 2023

CVE-2023-44156 is a sensitive information disclosure vulnerability in Acronis Cyber Protect 15 caused by spell-jacking, which allows attackers to access sensitive data. This affects Acronis Cyber Prot...

CVE-2023-44158

HIGH CVSS 7.5 Sep 27, 2023

Acronis Cyber Protect 15 versions before build 35979 insufficiently mask token fields, potentially exposing sensitive authentication or session tokens. This affects all users of Acronis Cyber Protect ...

CVE-2023-41749

HIGH CVSS 7.5 Aug 31, 2023

This vulnerability in Acronis Agent and Cyber Protect for Windows allows attackers to access sensitive system information through excessive data collection. It affects Windows systems running vulnerab...

CVE-2023-41743

HIGH CVSS 7.8 Aug 31, 2023

This CVE describes a local privilege escalation vulnerability in Acronis products for Windows. It allows a local low-privileged user to gain SYSTEM-level privileges by exploiting insecure driver commu...

CVE-2022-45451

HIGH CVSS 7.8 Aug 31, 2023

This CVE describes a local privilege escalation vulnerability in Acronis products for Windows. It allows a local attacker with low privileges to gain SYSTEM-level access due to insecure driver communi...

CVE-2023-41742

HIGH CVSS 7.5 Aug 31, 2023

This vulnerability allows attackers to exploit Acronis Agent and Acronis Cyber Protect 15 by binding to unrestricted IP addresses, creating an excessive attack surface. Affected systems include Acroni...

CVE-2022-45450

HIGH CVSS 7.5 May 18, 2023

This vulnerability allows unauthorized users to access and manipulate sensitive information in Acronis products due to improper authorization checks. It affects Acronis Agent and Acronis Cyber Protect...

CVE-2022-45453

HIGH CVSS 7.5 May 18, 2023

This vulnerability allows attackers to perform man-in-the-middle attacks by exploiting weak TLS/SSL cipher suites in Acronis Cyber Protect 15. Affected systems include Windows and Linux versions befor...

CVE-2022-45458

HIGH CVSS 7.5 May 18, 2023

This vulnerability allows attackers to bypass certificate validation in Acronis products, potentially leading to man-in-the-middle attacks, sensitive information disclosure, and unauthorized data mani...

CVE-2022-3405

HIGH CVSS 8.8 May 3, 2023

CVE-2022-3405 is a privilege escalation vulnerability in Acronis Agent that allows local attackers to execute arbitrary code and access sensitive information. This affects Acronis Cyber Protect 15 and...

CVE-2022-45454

HIGH CVSS 7.5 Feb 13, 2023

This vulnerability allows local users to access sensitive information due to insecure folder permissions in Acronis products on Windows. It affects Acronis Agent and Acronis Cyber Protect 15 installat...

CVE-2022-30993

HIGH CVSS 7.5 May 18, 2022

CVE-2022-30993 allows attackers to intercept sensitive information transmitted in cleartext between Acronis Cyber Protect components. This affects Acronis Cyber Protect 15 installations on Linux and W...

CVE-2022-24113

HIGH CVSS 7.8 Feb 4, 2022

This CVE describes a local privilege escalation vulnerability in Acronis Windows products where child processes receive excessive permissions. An attacker with local access can exploit this to gain SY...

CVE-2021-44204

HIGH CVSS 7.8 Feb 4, 2022

This vulnerability allows local attackers to escalate privileges on Windows systems by exploiting improper access control checks on named pipes. Attackers can gain SYSTEM-level privileges by connectin...

CVE-2021-44198

HIGH CVSS 7.8 Nov 29, 2021

This CVE describes a DLL hijacking vulnerability in Acronis Cyber Protect 15 for Windows that allows local attackers to escalate privileges by placing a malicious DLL in a location where the applicati...

CVE-2021-38088

HIGH CVSS 7.8 Aug 12, 2021

This vulnerability allows local attackers to escalate privileges on Windows systems running vulnerable versions of Acronis Cyber Protect 15. Attackers can hijack binaries to execute arbitrary code wit...

CVE-2024-55541

MEDIUM CVSS 6.1 Jan 2, 2025

A stored cross-site scripting (XSS) vulnerability in Acronis Cyber Protect 16 allows attackers to inject malicious scripts via postMessage without proper origin validation. When exploited, this could ...

CVE-2024-49382

MEDIUM CVSS 4.3 Oct 15, 2024

The archive-server service in Acronis Cyber Protect 16 binds to an unrestricted IP address, exposing unnecessary network attack surface. This affects Acronis Cyber Protect 16 installations on Linux an...

CVE-2024-49384

MEDIUM CVSS 4.3 Oct 15, 2024

The acep-collector service in affected Acronis Cyber Protect 16 versions binds to an unrestricted IP address, exposing unnecessary network attack surface. This allows attackers on the same network to ...

CVE-2022-45449

MEDIUM CVSS 6.5 Jul 16, 2024

Acronis Agent in Cyber Protect 15 has excessive privileges that can lead to sensitive information disclosure. This affects Acronis Cyber Protect 15 installations on Windows and Linux systems before bu...