CVE-2024-34014

MEDIUM

Acronis Backup - Improper Symbolic Link Handling

Title source: llm
STIX 2.1

Description

Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.

Scores

CVSS v3 5.5
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-61
Status published
Products (4)
Acronis/Acronis Backup extension for Plesk unspecified - 1.8.6.599
Acronis/Acronis Backup plugin for cPanel & WHM unspecified - 1.8.3.818
Acronis/Acronis Backup plugin for cPanel & WHM unspecified - 1.9.1.892
Acronis/Acronis Backup plugin for DirectAdmin unspecified - 1.2.2.181
Published Nov 11, 2024
Tracked Since Feb 18, 2026