10

CVE-2025-30411

Sensitive data disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, Windows) before build 41800.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Acronis ≫ Cyber Protect Version 15 Update -
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 15 Update update1
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 15 Update update2
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 15 Update update3
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 15 Update update4
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 15 Update update5
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 15 Update update6
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 16 Update -
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 16 Update update1
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 16 Update update2
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Acronis ≫ Cyber Protect Version 16 Update update3
   Linux ≫ Linux Kernel
   Microsoft ≫ Windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.487
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@acronis.com 10 3.9 6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-1390 Weak Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

https://security-advisory.acronis.com/advisories/SEC-8768
Vendor Advisory