PT-2020-14668 · Nakivo · Nakivo Backup & Replication Director

Published

2020-09-24

·

Updated

2022-04-05

·

CVE-2020-15850

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nakivo Backup & Replication Director version 9.4.0.r43656
Description The issue arises from insecure permissions, allowing local users to access the Nakivo Director web interface and potentially gain root privileges. This is due to the database, which contains web application users and the password-recovery secret value, being readable.
Recommendations For Nakivo Backup & Replication Director version 9.4.0.r43656, consider restricting access to the database containing user information and password-recovery secret values to prevent unauthorized access and potential privilege escalation. As a temporary workaround, limit local user access to the Nakivo Director web interface until a more secure configuration or update is available.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15850

Affected Products

Nakivo Backup & Replication Director