Show filters
96 Total Results
Displaying 11-20 of 96
Sort by:
Attacker Value
Unknown
CVE-2024-55542
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895.
0
Attacker Value
Unknown
CVE-2024-55541
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55540
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
0
Attacker Value
Unknown
CVE-2024-55539
Disclosure Date: December 23, 2024 (last updated January 05, 2025)
Weak algorithm used to sign RPM package. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux) before build 39185.
0
Attacker Value
Unknown
CVE-2024-49388
Disclosure Date: October 15, 2024 (last updated February 05, 2025)
Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
0
Attacker Value
Unknown
CVE-2024-49387
Disclosure Date: October 15, 2024 (last updated February 05, 2025)
Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
0
Attacker Value
Unknown
CVE-2024-49384
Disclosure Date: October 15, 2024 (last updated February 05, 2025)
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
0
Attacker Value
Unknown
CVE-2024-49383
Disclosure Date: October 15, 2024 (last updated February 05, 2025)
Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
0
Attacker Value
Unknown
CVE-2024-49382
Disclosure Date: October 15, 2024 (last updated February 05, 2025)
Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
0
Attacker Value
Unknown
CVE-2024-8903
Disclosure Date: September 23, 2024 (last updated September 23, 2024)
Local active protection service settings manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows, macOS) before build 38565.
0