CVE-2021-32581
Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- acronis/cyber protect cloud · acronis/cyber protection agent · acronis/true image
- Source
- cve@mitre.org
References
- https://kb.acronis.com/content/68413Vendor Advisory
- https://kb.acronis.com/content/68419Vendor Advisory
- https://kb.acronis.com/content/68648Vendor Advisory
- https://kb.acronis.com/content/68413Vendor Advisory
- https://kb.acronis.com/content/68419Vendor Advisory
- https://kb.acronis.com/content/68648Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.