Lucene search

K
cveAcronisCVE-2023-2782
HistoryMay 18, 2023 - 11:15 a.m.

CVE-2023-2782

2023-05-1811:15:09
CWE-285
CWE-863
Acronis
web.nvd.nist.gov
23
cve-2023-2782
acronis cyber infrastructure
sensitive information disclosure
improper authorization

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

9.0%

Sensitive information disclosure due to improper authorization. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.3.1-38.

Affected configurations

Nvd
Node
acroniscyber_infrastructureRange<5.3.1-38
VendorProductVersionCPE
acroniscyber_infrastructure*cpe:2.3:a:acronis:cyber_infrastructure:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Acronis",
    "product": "Acronis Cyber Infrastructure",
    "platforms": [
      "ACI"
    ],
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "5.3.1-38",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVE-2023-2782