ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

NAKIVO Backup & Replication vulnerability exploited by attackers (CVE-2024-48248)

criticalVulnerability exploited in the wildimportance 60CVE-2024-48248

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-48248
Unauthenticated absolute path traversal file read in NAKIVO Backup & Replication

NAKIVO Backup & Replication before version 11.0.0.88174 contains an absolute path traversal flaw (CWE-36) in the getImageByPath function exposed through the /c/router endpoint, which lets an attacker read arbitrary files from the server. Because the request requires no authentication and no user interaction (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), any party that can reach the NAKIVO web interface can send crafted requests to retrieve files. The impact can extend beyond file disclosure: the PhysicalDiscovery function stores credentials in cleartext, so files harvested via the traversal can expose credentials that may enable remote code execution across the enterprise. All organizations running affected versions are at risk, particularly those with the NAKIVO web UI reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-19 amid reports of active exploitation, and EPSS puts its 30-day exploitation probability at roughly 94%.

Do: Upgrade NAKIVO Backup & Replication to version 11.0.0.88174 or later; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance (or discontinue use) within the required timeframe. Until patched, restrict internet exposure of the NAKIVO web interface and /c/router endpoint, review logs for suspicious getImageByPath requests, and rotate credentials configured for PhysicalDiscovery since cleartext credential harvesting may have enabled broader compromise.

8.694% KEV PoC
  • NAKIVO Backup & Replication (Backup & Replication Director) all versions before 11.0.0.88174
moderate≈ tens of thousands of deployments (vendor marketing cites ~30k+ customers; only the subset with the web UI exposed to the internet, likely thousands, are…
Full article361 words · extracted from helpnetsecurity.com · click to collapse

A vulnerability (CVE-2024-48248) in NAKIVO Backup and Replication, a backup, ransomware protection and disaster recovery solution designed for organizations of all sizes and managed service providers (MSPs), is being actively exploited.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday, but it’s yet unknown whether the flaw is being leveraged by ransomware attackers, who often try to delete existing backups to make it more likely for victim organizations to pay a ransom.

About CVE-2024-48248

CVE-2024-48248 is an absolute path traversal vulnerability that may allow remote, unauthenticated attackers to read files on the affected system.

“Exploiting this vulnerability could expose sensitive data, including configuration files, backups, and credentials, potentially leading to data breaches or further security compromises,” the company says.

The vulnerability was discovered and reported to NAKIVO by watchTowr researchers in September 2024, and the company patched it in v11.0.0.88174 of the solution without mentioning it in the release notes. (The document has since been updated to declare the fixed flaw.)

Sonny Macdonald of the watchTowr team published a technical write-up about the vulnerability on February 26, 2025, as well as a PoC exploit for it, and expressed the hope that NAKIVO had reached out to customers in November to stress the need for a quick upgrade.

Judging by CISA’s notice, some customers haven’t moved quickly enough and have been compromised.

Update again!

CVE-2024-48248 affects NAKIVO Backup & Replication versions 10.11.3.86570 and earlier. The company advised customers to download and upgrade to NAKIVO Backup & Replication version 11.0.0.88174 or later, and to check system logs for unusual or unauthorized access attempts that may indicate exploitation.

Since then, two more versions have been released. The last one, v11.0.2, contains a fix for another critical vulnerability – an XML External Entity flaw discovered in NAKIVO Backup & Replication 11.0.1.89945 – which may also allow attackers to retrieve arbitrary files from the affected system.

“If exploited, this vulnerability could lead to data leakage, unauthorized system access, and the compromise of backup and replication processes, posing a significant security risk,” the company noted, and advised customers to upgrade to version 11.0.2.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/03/21/nakivo-backup-replication-vulnerability-exploited-by-attackers-cve-2024-48248/