vulnerability

Nakivo Backup and Replication CVE-2024-48248: Absolute Path Traversal

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Mar 4, 2025
Added
Apr 9, 2025
Modified
Apr 10, 2025

Description

This vulnerability allows attackers to read arbitrary files on the affected system without authentication. Exploiting this vulnerability could expose sensitive data, including configuration files, backups, and credentials, potentially leading to data breaches or further security compromises.

Solution

nakivo-backup-and-replication-update-to-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.