Skip to content
COOEY

EXPOSURES › CVE-2023-45249

CVE-2023-45249

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-45249 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wilddefault-credssupply-chain

Acronis Cyber Infrastructure shipped with default passwords enabling unauthenticated remote command execution.

This vulnerability allows attackers to execute arbitrary commands on Acronis-managed systems without authentication, directly violating NIST 800-171 access control requirements. DIB organizations must immediately audit all Acronis deployments and enforce credential rotation to prevent ransomware or data exfiltration.

Shame score — The vendor shipped a critical RCE flaw with default credentials that was actively exploited in the wild, representing a severe security oversight.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.