CVE-2017-3219
UnknownEPSS 0.47%
Last modified
CVE-2017-3219 is a vulnerability of currently unknown severity. Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Acronis | True Image | <= 2017 |
References
- http://www.securityfocus.com/bid/99128Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/489392Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/99128Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/489392Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-3219?
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
How severe is CVE-2017-3219?
Severity scoring for CVE-2017-3219 is pending analysis. The EPSS model estimates a 0.47% probability of exploitation in the next 30 days.
How do I fix CVE-2017-3219?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-3213The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does …
- CVE-2017-3214The Milwaukee ONE-KEY Android mobile application stores the …7.5
- CVE-2017-3215The Milwaukee ONE-KEY Android mobile application uses bearer…
- CVE-2017-3216WiMAX routers based on the MediaTek SDK (libmtk) that use a …
- CVE-2017-3217CalAmp LMU 3030 series OBD-II CDMA and GSM devices has an SM…
- CVE-2017-3218Samsung Magician 5.0 fails to validate TLS certificates for …
- CVE-2017-3221Blind SQL injection in Inmarsat AmosConnect 8 login form all…
- CVE-2017-3222Hard-coded credentials in AmosConnect 8 allow remote attacke…9.8
- CVE-2017-3223Dahua IP camera products using firmware versions prior to V2…
- CVE-2017-3224Open Shortest Path First (OSPF) protocol implementations may…
- CVE-2017-3225Das U-Boot is a device bootloader that can read its configur…
- CVE-2017-3226Das U-Boot is a device bootloader that can read its configur…
Are you affected by CVE-2017-3219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
