peter bassill · operator
$ cve CVE-2024-48248 JSON

CVE-2024-48248 KEV

8.6
HIGH · CVSS 3.1 · EPSS 94.4% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-04-09.

Description

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

Scoring

CVSS8.6 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS94.36% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-36
On CISA KEVyes — remediate by 2025-04-09
Public exploitnone known
Published2025-03-04
Last modified2026-09-24

CISA KEV

NameNAKIVO Backup and Replication Absolute Path Traversal Vulnerability
Added2025-03-19
Due2025-04-09
Vendor / productNAKIVO / Backup and Replication
Ransomware usenone reported

Affected (1)

VendorProduct
nakivobackup \& replication director

References

→ the Explorer  ·  watch your stack  ·  NVD