Vulnerabilities used by  Akira


This information is provided by Ransomware-Vulnerability-Matrix


This is the list of vulnerabilities that have been observed during intrusions by  
Akira

Vendor Product CVE Source
Cisco ASA & FTD  🔴  CVE-2023-20269 cisco.com
Cisco ASA & FTD  🌕  CVE-2023-20263 blog.talosintelligence.com
Cisco ASA & FTD  🟠  CVE-2020-3259 cisa.gov
Fortinet FortiOS  🔴  CVE-2022-40684 stairwell.com
Fortinet FortiOS  🌕  CVE-2019-6693 stairwell.com
Fortinet FortiClient  🔴  CVE-2023-48788 blog.talosintelligence.com
SonicWall SonicOS SSL-VPN  🔴  CVE-2024-40766 arcticwolf.com
Veeam Backup & Replication  🔴  CVE-2024-40711 @SophosXOps
Veeam Backup & Replication  🟠  CVE-2023-27532 sophos.com
VMware ESXi  🟠  CVE-2024-37085 ("ESX Admins") microsoft.com
VMware vSphere Client  🔴  CVE-2021-21972 qualys.com

CVE Severity Levels

Severity Score Range Description
⚪️ Low 0.1 - 3.9 Minor impact on the system; typically does not require immediate action.
🌕 Medium 4.0 - 6.9 Moderate impact; may require action but is generally not urgent.
🟠 High 7.0 - 8.9 Significant impact; needs attention soon to prevent potential exploitation.
🔴 Critical 9.0 - 10.0 Severe impact; requires immediate action due to the high risk of exploitation and potential for serious damage.