EXPOSURES › CVE-2023-45249
CVE-2023-45249
HIGH ⌖ ON CISA KEV · EXPLOITEDAcronis Cyber Infrastructure shipped with default passwords enabling unauthenticated remote command execution.
This vulnerability allows attackers to execute arbitrary commands on Acronis-managed systems without authentication, directly violating NIST 800-171 access control requirements. DIB organizations must immediately audit all Acronis deployments and enforce credential rotation to prevent ransomware or data exfiltration.
Shame score — The vendor shipped a critical RCE flaw with default credentials that was actively exploited in the wild, representing a severe security oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.