CVE-2017-3219

Published Jun 21, 2017

Last updated 21 days ago

Overview

Description
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
Source
cret@cert.org
NVD status
Deferred

Risk scores

CVSS 3.0

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
8.3
Impact score
10
Exploitability score
6.5
Vector string
AV:A/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

cret@cert.org
CWE-311
nvd@nist.gov
CWE-345

Social media

Hype score
Not currently trending

Configurations