July 29, 2024 · Applied Cybernetics Group
CVE-2023-45249 — Acronis Cyber Infrastructure (ACI)
Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
- Added to KEV
2024-07-29- Federal due date
2024-08-19- Vendor
- Acronis
- Product
- Cyber Infrastructure (ACI)
- EPSS
- 99.8th percentile (score 0.935, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-45249
CISA short description
Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.