Impact
The vulnerability allows the unnecessary transmission of cryptographic material, potentially exposing keys or certificates used by Acronis Cyber Protect 17. This can lead to confidentiality compromise of encryption assets and is classified as CWE‑522, authentication material exposure.
Affected Systems
Acronis Cyber Protect 17 running on Linux and Windows systems with builds older than 41186 are affected.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to require attacker access to the agent or server configuration to trigger the transmission; the advisement does not specify additional conditions.
OpenCVE Enrichment