CVE-2023-41751
https://notcve.org/view.php?id=CVE-2023-41751
Sensitive information disclosure due to improper token expiration validation. The following products are affected: Acronis Agent (Windows) before build 32047. Divulgación de información confidencial debido a una validación inadecuada de la caducidad del token. Los siguientes productos se ven afectados: Acronis Agent (Windows) anterior a la compilación 32047. • https://security-advisory.acronis.com/advisories/SEC-5615 • CWE-287: Improper Authentication •
CVE-2023-41750
https://notcve.org/view.php?id=CVE-2023-41750
Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 32047. Divulgación de información sensible por falta de autorización. Los siguientes productos se ven afectados: Acronis Agent (Linux, macOS, Windows) anterior a la compilación 32047. • https://security-advisory.acronis.com/advisories/SEC-5382 • CWE-862: Missing Authorization •
CVE-2023-41749
https://notcve.org/view.php?id=CVE-2023-41749
Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Windows) before build 32047, Acronis Cyber Protect 15 (Windows) before build 35979. Divulgación de información sensible debido a la recopilación excesiva de información del sistema. Los siguientes productos se ven afectados: Acronis Agent (Windows) antes de la compilación 32047, Acronis Cyber ??Protect 15 (Windows) antes de la compilación 35979. • https://security-advisory.acronis.com/advisories/SEC-5287 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-46869
https://notcve.org/view.php?id=CVE-2022-46869
Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278. Escalada de privilegios locales debido a un manejo inadecuado de enlaces blandos durante la instalación. Los siguientes productos se ven afectados: Acronis Cyber ??Protect Home Office (Windows) anterior a la compilación 40278 • https://security-advisory.acronis.com/advisories/SEC-3835 • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE-269: Improper Privilege Management CWE-610: Externally Controlled Reference to a Resource in Another Sphere •
CVE-2023-41748
https://notcve.org/view.php?id=CVE-2023-41748
Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203. • https://security-advisory.acronis.com/advisories/SEC-5816 • CWE-20: Improper Input Validation •