CVE-2024-48248

Confirmed PUBLISHED

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to...

NAKIVO · Backup & Replication Director
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.6 High EPSS 94.1%

At a Glance

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

edge cisa nuclei_scanner nessus_scanner
CVE Published
Mar 04, 2025
Exploitation Reported
Mar 19, 2025
CVSS
8.6 High
EPSS
94.1%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
NAKIVO
Backup & Replication Director

0 to < 11.0.0.88174

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.