CVE-2025-24832
CVE-2025-24832
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.4EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
27 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Acronis · Acronis Backup extension for PleskAcronis · Acronis Backup plugin for cPanel & WHMWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →