CVE Vulnerabilities

CVE-2022-45453

Inadequate Encryption Strength

Published: May 18, 2023 | Modified: May 26, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Cyber_protect Acronis * 15 (excluding)
Cyber_protect Acronis 15 (including) 15 (including)
Cyber_protect Acronis 15-update1 (including) 15-update1 (including)
Cyber_protect Acronis 15-update2 (including) 15-update2 (including)
Cyber_protect Acronis 15-update3 (including) 15-update3 (including)
Cyber_protect Acronis 15-update4 (including) 15-update4 (including)

Potential Mitigations

References