Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
References
Link | Resource |
---|---|
https://www.kb.cert.org/vuls/id/489392 | Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/99128 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-06-21 13:29
Updated : 2019-10-09 16:27
NVD link : CVE-2017-3219
Mitre link : CVE-2017-3219
JSON object : View
CWE
CWE-345
Insufficient Verification of Data Authenticity
Products Affected
acronis
- true_image