Description
Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.
Problem types
Product status
Any version before 40497
Any version before 41186
Credits
Airbus SecLab (mailto:vuln@airbus.com)
Quentin Liddell (mailto:vuln@airbus.com)
Mattéo Ricordeau (mailto:vuln@airbus.com)
Benoît Camredon (mailto:vuln@airbus.com)
References
security-advisory.acronis.com/advisories/SEC-8658 (SEC-8658)
security-advisory.acronis.com/SEC-9386 (SEC-9386)