1. Skip to navigation
  2. Skip to content
  3. Skip to secondary-content




Acronis True Image Echo Server FTP AES Encryption Security Bypass

Report ID: SA30856
Source: Secunia
Date of Discovery: 31.07.2008
Criticality: Low
Affects:
Acronis True Image Echo Enterprise Server 9.x

Compromise From: From remote
Compromise Type: Exposure of sensitive information

Summary

A security issue has been reported in Acronis True Image Echo Server, which can be exploited by malicious attackers to disclose sensitive information.

Detailed Description

A security issue has been reported in Acronis True Image Echo Server, which can be exploited by malicious attackers to disclose sensitive information.


The security issue is caused due to the application not correctly encrypting backups when the backup destination is an FTP server, which can be exploited to disclose sensitive information by e.g. intercepting the transfer.

The security issue is confirmed in Acronis True Image Echo Server build 8072 for Linux. Other versions may also be affected.

Solution

Do not rely on the encryption when backing up onto FTP servers.

Create local backups and transfer them manually.