2023-12-14 15:00:31 +00:00
{
"id" : "CVE-2023-48676" ,
"sourceIdentifier" : "security@acronis.com" ,
"published" : "2023-12-14T14:15:43.673" ,
2023-12-19 15:00:28 +00:00
"lastModified" : "2023-12-19T14:20:14.047" ,
"vulnStatus" : "Analyzed" ,
2023-12-14 15:00:31 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36943."
2023-12-19 15:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "Divulgaci\u00f3n y manipulaci\u00f3n de informaci\u00f3n sensible por falta de autorizaci\u00f3n. Los siguientes productos se ven afectados: Acronis Cyber Protect Cloud Agent (Windows) anterior a la compilaci\u00f3n 36943."
2023-12-14 15:00:31 +00:00
}
] ,
"metrics" : {
2023-12-19 15:00:28 +00:00
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.1 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.2
}
] ,
2023-12-14 15:00:31 +00:00
"cvssMetricV30" : [
{
"source" : "security@acronis.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" ,
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 3.3 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 1.4
}
]
} ,
"weaknesses" : [
2023-12-19 15:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-862"
}
]
} ,
2023-12-14 15:00:31 +00:00
{
"source" : "security@acronis.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-862"
}
]
}
] ,
2023-12-19 15:00:28 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:21:update12:*:*:*:*:*:*" ,
"matchCriteriaId" : "F13C19F5-D246-49B8-AC50-A2A33E42A4B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:21:update3:*:*:*:*:*:*" ,
"matchCriteriaId" : "25A39B45-AD7A-4466-9025-98F086FF7369"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:21:update6:*:*:*:*:*:*" ,
"matchCriteriaId" : "1F4887BE-8A9D-4FDA-8D61-240013F27CEE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:21:update7:*:*:*:*:*:*" ,
"matchCriteriaId" : "BF1F6E6A-7209-4A3F-BD91-5B7EF913A527"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update10:*:*:*:*:*:*" ,
"matchCriteriaId" : "58A27C80-FEF3-4A82-9C72-31EC236F7B18"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update11:*:*:*:*:*:*" ,
"matchCriteriaId" : "AA46A5D1-48CD-4CAC-B7BB-66E96C60B058"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update2:*:*:*:*:*:*" ,
"matchCriteriaId" : "9B2A46DB-EAE5-4AB0-B951-C4F7F2B72C33"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update3:*:*:*:*:*:*" ,
"matchCriteriaId" : "7A68AB88-B3F3-4028-A94F-FBB7F2511130"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update5:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CBFA456-3981-49D9-BD67-1BF5967EBFE1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update7:*:*:*:*:*:*" ,
"matchCriteriaId" : "71751A99-144B-41E3-BAEC-9650D8333C40"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update8:*:*:*:*:*:*" ,
"matchCriteriaId" : "642A5273-93FF-4B02-9519-A0CB586C5878"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:22:update9:*:*:*:*:*:*" ,
"matchCriteriaId" : "11536779-137C-4031-8AA2-EE7CF807230E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:uddate1:*:*:*:*:*:*" ,
"matchCriteriaId" : "DE302081-7B9F-4A84-88E5-FBE71F036F3B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update10:*:*:*:*:*:*" ,
"matchCriteriaId" : "252FD2AD-DC8B-44FD-AF1A-AD836CF2453A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update11:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B45ABA8-8404-468A-B9C1-8F239D213317"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update12:*:*:*:*:*:*" ,
"matchCriteriaId" : "709E6874-59DA-491D-A0EE-1FCC230C6D61"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update2:*:*:*:*:*:*" ,
"matchCriteriaId" : "524F2ED8-CA74-4C84-9A4D-626111E0C090"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update3:*:*:*:*:*:*" ,
"matchCriteriaId" : "F0DDE287-33E4-4A0D-AD16-9D6239DEF809"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update5:*:*:*:*:*:*" ,
"matchCriteriaId" : "E94AE028-4F33-4507-AE62-FB83046A7C2D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update6:*:*:*:*:*:*" ,
"matchCriteriaId" : "261677B5-2A5C-4FE7-A277-CC0268B308D6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update7:*:*:*:*:*:*" ,
"matchCriteriaId" : "6B675BDA-8979-403B-9281-42E92C88BE9D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update8:*:*:*:*:*:*" ,
"matchCriteriaId" : "D385D293-542B-414C-A344-3B6871D8E11B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:acronis:cyber_protect_cloud_agent:23:update9:*:*:*:*:*:*" ,
"matchCriteriaId" : "5830C1E7-CA7E-41E3-B556-3F006E8433DE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2572D17-1DE6-457B-99CC-64AFD54487EA"
}
]
}
]
}
] ,
2023-12-14 15:00:31 +00:00
"references" : [
{
"url" : "https://security-advisory.acronis.com/advisories/SEC-5905" ,
2023-12-19 15:00:28 +00:00
"source" : "security@acronis.com" ,
"tags" : [
"Vendor Advisory"
]
2023-12-14 15:00:31 +00:00
}
]
}