CVE-2024-49383
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 15, 2024
Updated: Feb 4, 2025
CWE ID 1327
Summary
CVE-2024-49383 is a newly discovered vulnerability affecting Acronis Cyber Protect 16, version prior to build 38690. This issue stems from the acep-importer service, which unnecessarily binds to an unrestricted IP address, expanding the attack surface. An attacker could potentially exploit this vulnerability to launch attacks on vulnerable systems, potentially leading to unauthorized access or data breaches. Both Linux and Windows versions of Acronis Cyber Protect 16 are impacted. Users are urged to upgrade to the latest build to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Acronis Cyber Protect
Affected Vendors
- Acronis International