CVE-2024-49384
Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.
Scoring
- Severity
- LOW
- CVSS base score
- 3.5
- CVSS vector
- CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-1327
- Published
- 2024-10-15
- Last modified
- 2026-03-13
Affected products
- Acronis Acronis Cyber Protect 16
Weakness type
Related vulnerabilities
- CVE-2026-75021 — fastify-cli vulnerable to remote code execution via ignored explicit Inspector bind address
- CVE-2026-20212 — Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability
- CVE-2026-82456 — argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-16713 — IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
- CVE-2026-55641 — 9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF
- CVE-2026-0481 — Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a...
- CVE-2026-42503 — Accidental binding to INADDR_ANY might lead to RCE in golang.org/x/tools/gopls