// For flags

CVE-2022-3405

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.

*Credits: Sandro Tolksdorf of usd AG (https://herolab.usd.de), @boldglum (https://hackerone.com/boldglum)
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-10-03 CVE Reserved
  • 2023-05-03 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-10-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-269: Improper Privilege Management
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
10130
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
10130
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
10330
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
10330
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
11010
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
11010
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
13160
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
13160
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
13400
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
13400
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
14280
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
14280
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
14330
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
14330
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
16180
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
16180
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
16318
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
16318
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
16327
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
16327
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
7641
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
7641
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
7970
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
7970
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
8850
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
8850
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
9010
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Backup
Search vendor "Acronis" for product "Cyber Backup"
12.5
Search vendor "Acronis" for product "Cyber Backup" and version "12.5"
9010
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
-
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
update1
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
update1
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
update2
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
update2
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
update3
Affected
in Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
--
Safe
Acronis
Search vendor "Acronis"
Cyber Protect
Search vendor "Acronis" for product "Cyber Protect"
15
Search vendor "Acronis" for product "Cyber Protect" and version "15"
update3
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe