CVE-2022-45458 MEDIUM

CVE-2022-45458

Vendor Acronis
Product Acronis Agent
Weakness CWE-295
Published May 18, 2023
Last update January 22, 2025

CVSS base score

4.2/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Sensitive information disclosure and manipulation due to improper certification validation. The following products are affected: Acronis Agent (Windows, macOS, Linux) before build 29633, Acronis Cyber Protect 15 (Windows, macOS, Linux) before build 30984.

Key dates

02Disclosure timeline

May 18, 2023 CVE published
January 22, 2025 Record updated