Vulnerability record · CVE-2023-45249 · published 24 July 2024
CVE-2023-45249: Acronis Cyber Infrastructure default password remote command execution
Acronis · Cyber Infrastructure
Acronis Cyber Infrastructure (ACI) ships with default passwords that allow remote command execution. The flaw affects multiple ACI builds before 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53 and 5.4.4-132. Because the credentials are default and reachable over the network, any exposed ACI instance is at immediate risk of full compromise.
Description
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network RCE via default passwords, listed in CISA KEV with confirmed in-the-wild exploitation and very high EPSS score.
What it is
Acronis Cyber Infrastructure (ACI) ships with default passwords that allow remote command execution. The flaw affects multiple ACI builds before 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53 and 5.4.4-132. Because the credentials are default and reachable over the network, any exposed ACI instance is at immediate risk of full compromise.
Impact
An unauthenticated attacker can execute arbitrary commands on the ACI host, leading to full control of the infrastructure management platform and any data or workloads it manages.
Attack surface
Reached over the network via the ACI management interface; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication or user interaction is required. Any ACI deployment reachable from an untrusted network is exposed.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2024-07-29, and press coverage reports exploitation in the wild. EPSS gives a 30-day probability of 0.53255 (98.9th percentile), indicating high likelihood of attempted exploitation.
What to do
- Upgrade ACI to a fixed build: 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53 or 5.4.4-132 (or later) as applicable to your branch.
- Immediately change all default passwords on ACI management and service accounts, and enforce strong unique credentials.
- Restrict network access to the ACI management interface to trusted management networks only; do not expose it to the internet.
- If patching is not immediately possible, follow the vendor advisory SEC-6452 mitigations or discontinue use of the product per CISA guidance.
- Audit ACI logs and accounts for signs of unauthorized access or command execution before and after remediation.
Detection
- Monitor ACI authentication logs for successful logins using default or known default credentials from unexpected source IPs.
- Alert on unexpected processes, command execution or outbound connections originating from ACI management hosts.
- Review network flow logs for external connections to ACI management ports that should be internal-only.
- Search for newly created accounts, scheduled tasks or configuration changes on ACI systems that were not authorized.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-45249 to the Known Exploited Vulnerabilities catalog on 29 July 2024 as "Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 19 August 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security-advisory.acronis.com/advisories/SEC-6452 | Vendor Advisory |
| https://www.securityweek.com/acronis-product-vulnerability-exploited-in-the-wild/ | Press/Media Coverage |
| https://security-advisory.acronis.com/advisories/SEC-6452 | Vendor Advisory |
| https://www.securityweek.com/acronis-product-vulnerability-exploited-in-the-wild/ | Press/Media Coverage |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-45249 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-45249 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-45249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.