What the vulnerability does

01Description

Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.

Key dates

02Disclosure timeline

June 21, 2017 CVE published
August 5, 2024 Record updated