logo

CVE-2024-48248 - NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

Project:NAKIVO

Product:Backup and Replication

Date Added:2025-03-19Due Date:2025-04-09

Vulnerability Name

NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

Description

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm

https://nvd.nist.gov/vuln/detail/CVE-2024-48248

Related News Articles

CISA Adds NAKIVO Vulnerability to KEV Catalog Amid Active ExploitationMarch 20, 2025