CVE-2021-32581 Information

Description

Acronis True Image prior to 2021 Update 4 for Windows Acronis True Image prior to 2021 Update 5 for Mac Acronis Agent prior to build 26653 Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Reference

https://kb.acronis.com/content/68413 https://kb.acronis.com/content/68419 https://kb.acronis.com/content/68648

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

NONE

Base Severity

8.1

Share on: