Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
The product does not encrypt sensitive or critical information before storage or transmission.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/99128 | vdb entry third party advisory |
https://www.kb.cert.org/vuls/id/489392 | third party advisory us government resource |