NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
References
Configurations
History
25 Mar 2025, 18:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nakivo:backup_\&_replication_director:*:*:*:*:*:*:*:* | |
First Time |
Nakivo
Nakivo backup \& Replication Director |
|
CWE | NVD-CWE-Other | |
References | () https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm - Product | |
References | () https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/ - Third Party Advisory | |
References | () https://github.com/watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248/?ref=labs.watchtowr.com - Exploit, Third Party Advisory |
20 Mar 2025, 01:00
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
04 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Mar 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
CWE | CWE-36 |
04 Mar 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-04 08:15
Updated : 2025-03-25 18:48
NVD link : CVE-2024-48248
Mitre link : CVE-2024-48248
CVE.ORG link : CVE-2024-48248
JSON object : View
Products Affected
nakivo
- backup_\&_replication_director
CWE