Developers: | Acronis |
Last Release Date: | 2019/07/26 |
Technology: | SDN Software-Defined Network Software-Defined Networks, Data Centers - Data Center Technologies |
Content |
Acronis Cyber Infrastructure (formerly Acronis Software-Defined Infrastructure) is a scalable solution for creating a software-defined infrastructure based on standard equipment and supporting all types of data workloads.
2024: Manufacturer's recognition of holes in products
At the end of July 2024, the Swiss cyber security technology and data protection company Acronis reported a dangerous vulnerability in its products. Exploiting the hole, attackers can perform remote execution of commands in the victim's system.
The problem (CVE-2023-45249) affecting the Acronis Cyber Infrastructure (ACI) platform is related to the use of default passwords. The breach is a critical hazard: she received a 9.8 out of 10 score on the CVSS scale. ACI is a unified solution that combines remote endpoint management, backup, and virtualization capabilities to support disaster recovery workloads. According to Acronis, in 2024, over 20,000 service providers use ACI to protect more than 750,000 enterprises in 150 countries around the world.
Attackers who fail authentication can exploit the vulnerability to remotely execute code on servers. Moreover, such attacks do not require interaction with the user. Acronis notes that cybercriminals are already exploiting the breach when organizing intrusions. Therefore, system administrators are advised to download the released updates as soon as possible. The flaw is present in the following products:
· ACI before assembly 5.0.1-61 (fixed in ACI 5.0 update 1.4);
· ACI before assembly 5.1.1-71 (fixed in ACI 5.1 update 1.2);
· ACI before assembly 5.2.1-69 (fixed in ACI 5.2 update 1.3);
· ACI before assembly 5.3.1-53 (fixed in ACI 5.3 update 1.3);
· ACI before assembly 5.4.4-132 (corrected in ACI 5.4 update 4.2).
CVE-2023-45249 relates to the vulnerability of remote execution of commands due to the use of default passwords. The Acronis team conducted a thorough analysis of the problem and concluded that it poses a critical danger, the company said in a notice.[1] |
2019
Acronis Cyber Infrastructure 3.0
On July 26, 2019, Acronis announced the release of Acronis Cyber Infrastructure 3.0, an update to its universal software-defined infrastructure solution. This solution, which can be deployed on any standard hardware, allows you to start virtual machines and store data.
According to the developer, the update from Acronis will allow partners and customers of the company to increase the efficiency, stability and security of their infrastructure, reduce operating costs through flexible licensing and provide support for various use cases, including virtual private cloud, hybrid cloud, private cloud and hybrid storage solution.
Acronis noted that with Acronis Cyber Infrastructure 3.0, customers get the ability to take snapshots of virtual machine volumes Linux and Windows flexible virtual network technologies with support for virtual routers and SNAT, static routes and floating IP addresses. Service providers can easily manage client resources with multitentance support and self-service capabilities that help end users monitor and track their resources. Service providers may also allow their logos and designs to be embedded in their solutions and their to integrate own, software such as billing and management. interaction with customers API Thanks to those compatible with, it's OpenStack simple, Acronis claims. Acronis Backup Many improvements have been added to the Gateway component: an intuitive interface for georeplication, data asynchronous replication, which makes it easier for clients to create backups. storages
"For Acronis, this update is an important step forward in providing customers with comprehensive cyber defense solutions. Acronis Cyber Infrastructure is a solid foundation for Acronis' cyber defense services. This is the foundation of our concept of providing complete and end-to-end cyber defense. Acronis simplifies data protection processes for customers so they can focus on their core activities, " noted Sergey Belousov, founder and CEO of Acronis |
According to the developer, Acronis Cyber Infrastructure 3.0 enhances the company's ability to provide complete cyber protection for customers and partners, covering all five of its areas: security, availability, privacy, authenticity and security (SAPAS). This comprehensive approach helps companies cope with the various challenges faced by today's IT teams, including increasing complexity, security challenges, and increased costs. With this update, Acronis extends the ability to easily, efficiently, and reliably protect data, applications, and systems for all of the company's customers.
Changes and additions to Acronis Cyber Infrastructure 3.0, noted by the developer:
- A self-service portal for effectively providing resources to end users in multi-user systems with independent task and project isolation in a common environment.
- Linux and OS Microsoft Windows-compatible snapshots of virtual machine volumes based on application performance.
- High availability for virtual machines with automatic resumption in the event of a failure.
- Acronis Backup Gateway georeplication with asynchronous replication and failover between Acronis Cyber Infrastructure 3.0 clusters.
- Control Panel for Acronis Cyber Infrastructure Storage Appliance and updated Device Configuration Wizard.
Rebranding
On April 25, 2019, Acronis announced the rebranding of the Acronis Software-Defined Infrastructure product. The decision began to be called Acronis Cyber Infrastructure.