CVE-2023-45249
CRITICAL CISA KEVDescription
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| acronis | cyber_infrastructure |
| acronis | cyber_infrastructure |
| acronis | cyber_infrastructure |
| acronis | cyber_infrastructure |
| acronis | cyber_infrastructure |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-45249? +
How severe is CVE-2023-45249? +
What products are affected by CVE-2023-45249? +
How do I check if I'm vulnerable to CVE-2023-45249? +
Related Vulnerabilities
The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username …
An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH …
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require …
An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain …
A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default …
Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.