CVE Feed

    Dashboard / CVE / CVE-2020-16171

    CVE-2020-16171

    An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against otherwise unreachable Acronis services that are bound to localhost such as the NotificationService on 127.0.0.1:30572.

    Published:Sep 21, 2020
    Last Modified:Nov 21, 2024
    EPS:Sep 21, 2020
    EPSS Score:0.11242
    CVSS Score:6.5

    Affected Products

    Vendor
    Acronis
    Product
    Cyber Backup

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High