CVE Vulnerabilities

CVE-2022-24115

Improper Verification of Cryptographic Signature

Published: Feb 04, 2022 | Modified: Feb 10, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
True_image Acronis 2021 (including) 2021 (including)
True_image Acronis 2021-update_1 (including) 2021-update_1 (including)
True_image Acronis 2021-update_2 (including) 2021-update_2 (including)
True_image Acronis 2021-update_3 (including) 2021-update_3 (including)
True_image Acronis 2021-update_4 (including) 2021-update_4 (including)

References