LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 29, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 19, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-45249 to its Known Exploited Vulnerabilities catalog on Jul 29, 2024, with a federal patch deadline of Aug 19, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.

CVE-2023-45249 is an insecure default password issue in Acronis Cyber Infrastructure (ACI). Because default credentials are present, an unauthenticated remote attacker can gain access and execute commands on the system. This matters for IT and security teams because ACI often sits in storage, backup, or infrastructure layers; successful abuse can give an attacker a foothold for further movement, data access, or disruption of recovery capabilities.

Public detail is limited to the CISA summary and the CWE classification. Confirm exact product builds, fixed releases, and configuration guidance against the vendor advisory before acting.

How it works

The weakness is classified as CWE-1393, which covers the use of default passwords. In this case, Acronis Cyber Infrastructure ships or retains credentials that are known or easily guessed. An attacker who can reach the management or service interface simply authenticates with those defaults and then issues commands as if they were a legitimate administrator.

No further exploit mechanics are provided in the available facts. The practical result is remote command execution without prior authentication. Defenders should treat any exposed ACI management plane that still uses factory credentials as fully compromised once an attacker reaches it. Specific authentication endpoints, protocols, or command channels must be verified in the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

Acronis Cyber Infrastructure is typically deployed as a software-defined storage or hyper-converged platform supporting backup, object storage, or virtualization workloads. It commonly runs on dedicated appliance-like servers or clusters inside data centers and private clouds.

If you cannot confirm version or credential state, treat the instance as potentially affected until verified.

How to remediate

Patch first. Apply the vendor-supplied update or configuration changes named in the Acronis advisory for CVE-2023-45249. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Do not rely on generic “change password” advice alone; follow the precise steps and package names given by the vendor.

If you can't patch immediately

Reduce the attack surface until the official fix can be applied.

These controls buy time; they do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently lead to full system compromise and subsequent data access or ransomware staging, although ransomware use is not documented for this specific CVE. If logs show successful default-credential logins or unexplained command activity, treat the ACI environment and any attached storage as potentially breached. Isolate the systems, preserve forensic images, rotate all credentials that may have been accessible from the platform, and begin incident-response procedures. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAcronis · Cyber Infrastructure (ACI)
WeaknessCWE-1393
Added to CISA KEVJul 29, 2024
Federal patch deadlineAug 19, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities