HIGH

CVE-2024-48248

Nakivo Backup \& Replication Director 2025-03-04 CVSS v3.1
CVSS
8.6
KEV

Description

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

Summary dbcve.org

NAKIVO Backup & Replication versions prior to 11.0.0.88174 contain an absolute path traversal vulnerability in the /c/router endpoint via the getImageByPath parameter, allowing authenticated attackers to read arbitrary files from the filesystem. This can potentially lead to remote code execution as the PhysicalDiscovery component stores credentials in cleartext.

Mitigation

Upgrade to NAKIVO Backup & Replication version 11.0.0.88174 or later. If immediate patching is not feasible, implement network-level access controls to restrict the /c/router endpoint to trusted IP addresses only.

Proof of Concept

Weakness (CWE)

CWE-36

EPSS Score

94.36%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE