Lucene search

K
cveAcronisCVE-2023-48683
HistoryApr 29, 2024 - 4:15 p.m.

CVE-2023-48683

2024-04-2916:15:34
CWE-862
Acronis
web.nvd.nist.gov
34
information disclosure
missing authorization
acronis cyber protect cloud agent
linux
macos
windows
nvd

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

9.0%

Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 37758.

CNA Affected

[
  {
    "vendor": "Acronis",
    "product": "Acronis Cyber Protect Cloud Agent",
    "platforms": [
      "Linux",
      "macOS",
      "Windows"
    ],
    "versions": [
      {
        "version": "unspecified",
        "status": "affected",
        "lessThan": "37758",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

6.5

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2023-48683