๐Ÿ” CVE Alert

CVE-2023-45249

CRITICAL 9.8 โš ๏ธ CISA KEV
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

CWE CWE-1393
Vendor acronis
Product acronis cyber infrastructure
Published Jul 24, 2024
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for acronis acronis cyber infrastructure

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-45249.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Versions

Acronis / Acronis Cyber Infrastructure
unspecified < 5.0.1-61
Acronis / Acronis Cyber Infrastructure
unspecified < 5.1.1-71
Acronis / Acronis Cyber Infrastructure
unspecified < 5.2.1-69
Acronis / Acronis Cyber Infrastructure
unspecified < 5.3.1-53
Acronis / Acronis Cyber Infrastructure
unspecified < 5.4.4-132

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security-advisory.acronis.com: https://security-advisory.acronis.com/advisories/SEC-6452 securityweek.com: https://www.securityweek.com/acronis-product-vulnerability-exploited-in-the-wild/ cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-45249