4

CVE-2024-55538

Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736, Acronis True Image OEM (macOS) before build 42571, Acronis True Image OEM (Windows) before build 42575.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAcronis
Produkt Acronis True Image
Default Statusunaffected
Version unspecified
Version < 41725
Status affected
HerstellerAcronis
Produkt Acronis True Image
Default Statusunaffected
Version unspecified
Version < 41736
Status affected
HerstellerAcronis
Produkt Acronis True Image OEM
Default Statusunaffected
Version unspecified
Version < 42571
Status affected
HerstellerAcronis
Produkt Acronis True Image OEM
Default Statusunaffected
Version unspecified
Version < 42575
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.072
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@acronis.com 4 2.5 1.4
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

https://security-advisory.acronis.com/advisories/SEC-2209