CVE-2023-45249
Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.8
- EPSS
- 53.5% 백분위 98.9% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2024.08.19
- 공개일
- 2024.07.24
CISA KEV에 등록된 실제 악용 확인 취약점
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
공급사 Acronis
제품 Cyber Infrastructure (ACI)
영향 버전 unspecified, 0, 5.1.1, 5.2.1, 5.3.1, 5.4.4, < 5.0.1-61, >= 5.1.1 < 5.1.1-71, >= 5.2.1 < 5.2.1-69, >= 5.3.1 < 5.3.1-53, >= 5.4.4 < 5.4.4-132
수정 버전 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, 5.4.4-132
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
조치 기한: 2024.08.19CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-1393
KEV 등록일 2024.07.29
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://security-advisory.acronis.com/advisories/SEC-6452; https://nvd.nist.gov/vuln/detail/CVE-2023-45249
EPSS 데이터 기준일 2026.06.27