CVE-2023-45249
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before bu...
Affects 1 product across 1 vendor.
CVE-2023-45249 affects multiple versions of Acronis Cyber Infrastructure (ACI), allowing remote command execution due to the use of default passwords. This vulnerability has a high CVSS score of 9.8, indicating critical severity. Immediate action is required to mitigate the risk of unauthorized access and potential system compromise.
BSID: BS-2024-GLOBAL-346714-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2023-45249?
What is the CVSS score for CVE-2023-45249?
Is CVE-2023-45249 actively exploited?
How do I remediate CVE-2023-45249?
What systems are affected by CVE-2023-45249?
What NERC-CIP standard applies to CVE-2023-45249?
What IEC 62443 requirement maps to CVE-2023-45249?
| CVE ID | CVE-2023-45249 |
|---|---|
| BSID | BS-2024-GLOBAL-346714-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2024-07-24 |
| Last Modified | 2025-10-22 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Source | NVD |
Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from the use of default passwords in the affected versions of Acronis Cyber Infrastructure (ACI). An attacker can exploit this by remotely connecting to the system and executing arbitrary commands, leading to full control over the affected systems. This can result in data theft, system disruption, and further lateral movement within the network.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Acronis | Cyber Infrastructure | — |
| CISA KEV | ● Active Exploitation Confirmed (added 2024-07-29) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strong password policies and change all default passwords immediately. Enable multi-factor authentication (MFA) where possible to add an additional layer of security.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 because it involves the use of default passwords, which can be easily exploited to gain unauthorized access to critical systems, compromising the security of the electronic security perimeter.
This CVE maps to SR 7.6 because it involves the use of default credentials, which can be exploited to gain unauthorized access to the system, violating the requirement for secure user authentication and access control.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 1203cb9b26a263e249336ae51da09c829f96e387db0c7e428a722ff008d38053e62275302ce389d31762d620670de7a6c135c8c33878e4560eb249fc58375ed6 |
This Vulnerability Is Being Actively Exploited
CVE-2023-45249 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →