CVE-2023-45249: Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-07-29. EPSS: 53.3% chance of exploitation in the next 30 days.

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) before build 5.1.1-71, Acronis Cyber Infrastructure (ACI) before build 5.2.1-69, Acronis Cyber Infrastructure (ACI) before build 5.3.1-53, Acronis Cyber Infrastructure (ACI) before build 5.4.4-132.

Affected products

  • Acronis Cyber Infrastructure: before 5.0.1-61 (fixed in 5.0.1-61); from 5.1.1, before 5.1.1-71 (fixed in 5.1.1-71); from 5.2.1, before 5.2.1-69 (fixed in 5.2.1-69); from 5.3.1, before 5.3.1-53 (fixed in 5.3.1-53); from 5.4.4, before 5.4.4-132 (fixed in 5.4.4-132)

Published 2024-07-24. Last modified 2026-06-17.