PT-2025-15441 · Nakivo · Nakivo Backup & Replication

Published

2025-04-07

·

Updated

2025-04-08

·

CVE-2025-32406

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: NAKIVO Backup & Replication versions 10.3.x through 11.0.1
Description: The issue is related to an XXE problem in the Director NBR component, allowing remote attackers to fetch and parse the XML response.
Recommendations: For versions 10.3.x through 11.0.1, update to version 11.0.2 to resolve the issue.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2026-00040
CVE-2025-32406

Affected Products

Nakivo Backup & Replication