PT-2025-8692 · Nakivo · Nakivo Backup & Replication

Sonny

·

Published

2025-02-26

·

Updated

2025-07-01

·

CVE-2024-48248

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NAKIVO Backup & Replication (affected versions not specified)
Description The issue concerns an arbitrary file read vulnerability in NAKIVO Backup & Replication. Over 4,100 services have been found to be vulnerable. Approximately 208 vulnerable instances were detected as of February 26, 2025, and over 3,100 exposed targets have been identified. The vulnerability allows hackers to access sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-02355
CVE-2024-48248

Affected Products

Nakivo Backup & Replication