CVE-2023-45249

● KEV CRITICAL

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before bu...

Affects 1 product across 1 vendor.

BCS9.38
CVSS 3.19.8
EPSS53.3%
Percentile99th
PatchPatched
KEV Added2024-07-29
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-1393: CWE-1393
◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2023-45249 affects multiple versions of Acronis Cyber Infrastructure (ACI), allowing remote command execution due to the use of default passwords. This vulnerability has a high CVSS score of 9.8, indicating critical severity. Immediate action is required to mitigate the risk of unauthorized access and potential system compromise.

BSID: BS-2024-GLOBAL-346714-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-45249?
CVE-2023-45249 affects multiple versions of Acronis Cyber Infrastructure (ACI), allowing remote command execution due to the use of default passwords. This vulnerability has a high CVSS score of 9.8, indicating critical severity. Immediate action is required to mitigate the risk of unauthorized access and potential system compromise.
What is the CVSS score for CVE-2023-45249?
CVE-2023-45249 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 53.3%.
Is CVE-2023-45249 actively exploited?
Yes. CVE-2023-45249 is in the CISA KEV catalog (added 2024-07-29). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2023-45249?
Priority: IMMEDIATE. Advisory: https://security-advisory.acronis.com/advisories/SEC-6452 PSIRT: [email protected]
What systems are affected by CVE-2023-45249?
CVE-2023-45249 affects: Acronis.
What NERC-CIP standard applies to CVE-2023-45249?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it involves the use of default passwords, which can be easily exploited to gain unauthorized access to critical systems, compromising the security of the electronic security perimeter.
What IEC 62443 requirement maps to CVE-2023-45249?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the use of default credentials, which can be exploited to gain unauthorized access to the system, violating the requirement for secure user authentication and access control.
Vulnerability Details
CVE IDCVE-2023-45249
BSIDBS-2024-GLOBAL-346714-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2024-07-24
Last Modified2025-10-22
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from the use of default passwords in the affected versions of Acronis Cyber Infrastructure (ACI). An attacker can exploit this by remotely connecting to the system and executing arbitrary commands, leading to full control over the affected systems. This can result in data theft, system disruption, and further lateral movement within the network.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Acronis Cyber Infrastructure
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 731 Days
CISA KEV● Active Exploitation Confirmed (added 2024-07-29)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strong password policies and change all default passwords immediately. Enable multi-factor authentication (MFA) where possible to add an additional layer of security.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it involves the use of default passwords, which can be easily exploited to gain unauthorized access to critical systems, compromising the security of the electronic security perimeter.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the use of default credentials, which can be exploited to gain unauthorized access to the system, violating the requirement for secure user authentication and access control.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash1203cb9b26a263e249336ae51da09c829f96e387db0c7e428a722ff008d38053e62275302ce389d31762d620670de7a6c135c8c33878e4560eb249fc58375ed6
Related CVEs affecting Acronis
CVE-2025-30416 10.0 Sensitive data disclosure and manipulation due to missing authorization. The ... CVE-2025-30411 10.0 Sensitive data disclosure and manipulation due to improper authentication. Th... CVE-2025-30412 10.0 Sensitive data disclosure and manipulation due to improper authentication. Th... CVE-2024-8767 9.9 Sensitive data disclosure and manipulation due to unnecessary privileges assi... CVE-2023-41746 9.8 Remote command execution due to improper input validation. The following prod...
View all Acronis CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2023-45249 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →