vulnerability
Nakivo Backup and Replication CVE-2024-48248: Absolute Path Traversal
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:C/I:N/A:N) | Mar 4, 2025 | Apr 9, 2025 | Apr 10, 2025 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Mar 4, 2025
Added
Apr 9, 2025
Modified
Apr 10, 2025
Description
This vulnerability allows attackers to read arbitrary files on the affected system without authentication. Exploiting this vulnerability could expose sensitive data, including configuration files, backups, and credentials, potentially leading to data breaches or further security compromises.
Solution
nakivo-backup-and-replication-update-to-latest
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.