Acronis Cyber Protect

CPE Details

Acronis Cyber Protect
-
2020-10-30
15h10 +00:00
2020-10-30
15h10 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:acronis:cyber_protect:-:*:*:*:*:*:*:*

Informations

Vendor

acronis

Product

cyber_protect

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-49388 2024-10-15 10h34 +00:00 Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
9.1
Critique
CVE-2024-49387 2024-10-15 10h34 +00:00 Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
7.5
Haute
CVE-2024-49384 2024-10-15 10h33 +00:00 Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
4.3
Moyen
CVE-2024-49383 2024-10-15 10h33 +00:00 Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
4.3
Moyen
CVE-2024-49382 2024-10-15 10h32 +00:00 Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
4.3
Moyen
CVE-2023-48682 2024-02-27 16h53 +00:00 Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
5.4
Moyen
CVE-2023-48681 2024-02-27 16h52 +00:00 Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
6.1
Moyen
CVE-2023-48680 2024-02-27 16h51 +00:00 Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391.
5.5
Moyen
CVE-2023-48679 2024-02-27 16h45 +00:00 Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
5.4
Moyen
CVE-2023-48678 2024-02-27 16h45 +00:00 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
5.5
Moyen
CVE-2023-44207 2023-09-27 12h02 +00:00 Stored cross-site scripting (XSS) vulnerability in protection plan name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
5.4
Moyen
CVE-2023-44206 2023-09-27 12h02 +00:00 Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
9.1
Critique
CVE-2023-44159 2023-09-27 12h02 +00:00 Sensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
7.5
Haute
CVE-2023-44156 2023-09-27 12h01 +00:00 Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
7.5
Haute
CVE-2023-44205 2023-09-27 12h01 +00:00 Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
5.3
Moyen
CVE-2023-44161 2023-09-27 12h01 +00:00 Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
6.5
Moyen
CVE-2023-44160 2023-09-27 12h01 +00:00 Sensitive information manipulation due to cross-site request forgery. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
6.5
Moyen
CVE-2023-44158 2023-09-27 12h01 +00:00 Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
7.5
Haute
CVE-2023-44157 2023-09-27 12h01 +00:00 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 35979.
7.8
Haute
CVE-2023-44155 2023-09-27 12h00 +00:00 Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
7.5
Haute
CVE-2023-44154 2023-09-27 12h00 +00:00 Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
8.1
Haute
CVE-2023-44153 2023-09-27 12h00 +00:00 Sensitive information disclosure due to cleartext storage of sensitive information in memory. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
7.5
Haute
CVE-2023-44152 2023-09-27 11h59 +00:00 Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
9.1
Critique
CVE-2022-45450 2023-05-18 09h27 +00:00 Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 28610, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 30984.
7.5
Haute
CVE-2022-45459 2023-05-18 09h26 +00:00 Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.
7.5
Haute
CVE-2022-45458 2023-05-18 09h25 +00:00 Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.
7.5
Haute
CVE-2022-45457 2023-05-18 09h23 +00:00 Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows) before build 29633, Acronis Cyber Protect 15 (Windows) before build 30984.
7.5
Haute
CVE-2022-45452 2023-05-18 09h21 +00:00 Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windows) before build 30430, Acronis Cyber Protect 15 (Windows) before build 30984.
7.8
Haute
CVE-2022-45453 2023-05-18 09h19 +00:00 TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.
7.5
Haute
CVE-2022-30991 2022-05-18 19h43 +00:00 HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
6.1
Moyen
CVE-2022-30992 2022-05-18 19h42 +00:00 Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
6.1
Moyen
CVE-2022-30993 2022-05-18 19h42 +00:00 Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
7.5
Haute
CVE-2022-30994 2022-05-18 19h41 +00:00 Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240
7.5
Haute
CVE-2022-30990 2022-05-18 19h38 +00:00 Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037
7.5
Haute
CVE-2021-44200 2021-11-29 18h19 +00:00 Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
5.4
Moyen
CVE-2021-44199 2021-11-29 18h19 +00:00 DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Windows) before build 39612
5.5
Moyen
CVE-2021-44202 2021-11-29 18h19 +00:00 Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
5.4
Moyen
CVE-2021-44203 2021-11-29 18h19 +00:00 Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
5.4
Moyen
CVE-2021-44198 2021-11-29 18h18 +00:00 DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035
7.8
Haute
CVE-2021-44201 2021-11-29 18h18 +00:00 Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
6.1
Moyen
CVE-2021-38087 2021-08-12 11h44 +00:00 Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
6.1
Moyen
CVE-2021-38086 2021-08-12 11h42 +00:00 Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
7.8
Haute
CVE-2021-38088 2021-08-12 11h38 +00:00 Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
7.8
Haute
CVE-2020-35556 2021-02-22 01h17 +00:00 An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.
7.5
Haute
CVE-2020-35664 2021-02-22 01h13 +00:00 An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.
6.1
Moyen
CVE-2020-10138 2020-10-21 11h40 +00:00 Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can create the appropriate path to a specially-crafted openssl.cnf file to achieve arbitrary code execution with SYSTEM privileges.
7.8
Haute