CVE-2024-34014: Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for...

Medium (5.5)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.3.818, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.6.599, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.2.181.

Classification

CVE ID: CVE-2024-34014

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.5

CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Problem Types

CWE-61

Affected Products

Vendor: Acronis, Acronis, Acronis, Acronis

Product: Acronis Backup plugin for cPanel & WHM, Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for Plesk, Acronis Backup plugin for DirectAdmin

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 0.1198 (how common is this exploit)

EPSS Date: 2025-03-14 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

Timeline