CVE-2024-48248
KEVHIGH 8.6EPSS 94.4%
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
- CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - CVSS v3.1
- 8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - EPSS
- 94.36% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-03-19
- Nuclei
- high
- Published
- 2025-03-04
- Updated
- 2025-10-21
Proof-of-concept exploits (1)
- watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-482483★ · 2025-02-16