NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
References
Configurations
History
21 Oct 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Mar 2025, 18:48
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:nakivo:backup_\&_replication_director:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-Other | |
| First Time |
Nakivo backup \& Replication Director
Nakivo |
|
| References | () https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm - Product | |
| References | () https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/ - Third Party Advisory | |
| References | () https://github.com/watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248/?ref=labs.watchtowr.com - Exploit, Third Party Advisory |
20 Mar 2025, 01:00
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
04 Mar 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Mar 2025, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
| CWE | CWE-36 |
04 Mar 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-03-04 08:15
Updated : 2025-10-21 23:16
NVD link : CVE-2024-48248
Mitre link : CVE-2024-48248
CVE.ORG link : CVE-2024-48248
JSON object : View
Products Affected
nakivo
- backup_\&_replication_director
CWE
