NAKIVO Backup & Replication Director contains an absolute path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files and potentially achieve remote code execution. The vulnerability is actively being exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-03-04
Added to CISA KEV: 2025-03-19 15 DAYS BETWEEN CVE AND KEV
CVE-2024-48248 is a critical security vulnerability affecting NAKIVO Backup & Replication. Below is a summary of the known details regarding this flaw.
CVE-2024-48248 Detail · Description · Metrics · References to Advisories, Solutions, and Tools · This CVE is in CISA's Known Exploited Vulnerabilities Catalog. ... An official website of the United States government Here's how you know ... CVE-2024-48248 Detail. Description. NAKIVO Backup & Replicat…
We're here to talk about an unauthenticated Arbitrary File Read vulnerability we discovered in NAKIVO's Backup and Replication solution.
The vulnerability has been confirmed to have a known exploit, meaning that attackers may leverage this weakness to gain unauthorized access and ... Risk & Impact Analysis The real-world deployment risk associated with CVE-2024-48248 is significant. Organizations that utilize Nakivo Backup & Replicat…
CVE-2024-48248 is a path traversal flaw in NAKIVO Backup & Replication Director allowing attackers to read arbitrary files, potentially leading to remote code execution. This article covers technical details, impact, and mitigation. Published: April 15, 2026 ... This vulnerability has been added to…