6.5

CVE-2020-16171

Exploit
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Acronis ≫ Cyber Backup Version <= 12.5
Acronis ≫ Cyber Backup Version 12.5 Update -
Acronis ≫ Cyber Backup Version 12.5 Update 10130
Acronis ≫ Cyber Backup Version 12.5 Update 10330
Acronis ≫ Cyber Backup Version 12.5 Update 11010
Acronis ≫ Cyber Backup Version 12.5 Update 13160
Acronis ≫ Cyber Backup Version 12.5 Update 13400
Acronis ≫ Cyber Backup Version 12.5 Update 14280
Acronis ≫ Cyber Backup Version 12.5 Update 14330
Acronis ≫ Cyber Backup Version 12.5 Update 16180
Acronis ≫ Cyber Backup Version 12.5 Update 16318
Acronis ≫ Cyber Backup Version 12.5 Update 16327
Acronis ≫ Cyber Backup Version 12.5 Update 7641
Acronis ≫ Cyber Backup Version 12.5 Update 7970
Acronis ≫ Cyber Backup Version 12.5 Update 8850
Acronis ≫ Cyber Backup Version 12.5 Update 9010
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.51% 0.918
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

http://seclists.org/fulldisclosure/2020/Sep/33
Third Party Advisory
Exploit
Mailing List
https://www.rcesecurity.com/2020/09/CVE-2020-16171-Exploiting-Acronis-Cyber-Backup-for-Fun-and-Emails/
Third Party Advisory