ZeroHour

CVE-2024-48248

KEV PoC moderate

Unauthenticated absolute path traversal file read in NAKIVO Backup & Replication

CISA: NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

CVSS 3.1
8.6 high
EPSS
94%p100
Published
()
KEV added
AI analysis

NAKIVO Backup & Replication before version 11.0.0.88174 contains an absolute path traversal flaw (CWE-36) in the getImageByPath function exposed through the /c/router endpoint, which lets an attacker read arbitrary files from the server. Because the request requires no authentication and no user interaction (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), any party that can reach the NAKIVO web interface can send crafted requests to retrieve files. The impact can extend beyond file disclosure: the PhysicalDiscovery function stores credentials in cleartext, so files harvested via the traversal can expose credentials that may enable remote code execution across the enterprise. All organizations running affected versions are at risk, particularly those with the NAKIVO web UI reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-19 amid reports of active exploitation, and EPSS puts its 30-day exploitation probability at roughly 94%.

What to do: Upgrade NAKIVO Backup & Replication to version 11.0.0.88174 or later; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance (or discontinue use) within the required timeframe. Until patched, restrict internet exposure of the NAKIVO web interface and /c/router endpoint, review logs for suspicious getImageByPath requests, and rotate credentials configured for PhysicalDiscovery since cleartext credential harvesting may have enabled broader compromise.

Affected
NAKIVO Backup & Replication (Backup & Replication Director)all versions before 11.0.0.88174
Estimated exposure
moderate≈ tens of thousands of deployments (vendor marketing cites ~30k+ customers; only the subset with the web UI exposed to the internet, likely thousands, are… — NAKIVO Backup & Replication is an on-premises backup product aimed at SMB and mid-market environments with a claimed customer base in the tens of thousands, but this network-reachable flaw is only remotely exploitable where the web…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

CISA Known Exploited Vulnerability
Affected
NAKIVO Backup and Replication
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
nakivo
Products
backup \& replication director
Weakness
CWE-36
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news