← Vulnerability feed

Vulnerability record · CVE-2024-48248 · published 4 March 2025

CVE-2024-48248: NAKIVO Backup & Replication absolute path traversal file read

Nakivo · Backup \& Replication Director

NAKIVO Backup & Replication before 11.0.0.88174 exposes the getImageByPath endpoint at /c/router, which fails to restrict file paths and allows absolute path traversal to read arbitrary files. Because PhysicalDiscovery stores cleartext credentials, reading those files can hand an attacker the credentials needed to move laterally and execute code across the enterprise.

8.6 CVSS 3.1 High CISA KEV since 19 Mar 2025 EPSS 94% · top 0.1% CWE-36 · CWE-36
8.6CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
24 Sep 2026Last modified by NVD

Description

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with a near-maximum EPSS score, requires no authentication, and can expose cleartext credentials that enable enterprise-wide compromise.

What it is

NAKIVO Backup & Replication before 11.0.0.88174 exposes the getImageByPath endpoint at /c/router, which fails to restrict file paths and allows absolute path traversal to read arbitrary files. Because PhysicalDiscovery stores cleartext credentials, reading those files can hand an attacker the credentials needed to move laterally and execute code across the enterprise.

Impact

An unauthenticated attacker can read arbitrary files from the appliance, including configuration and credential material. Those cleartext PhysicalDiscovery credentials can be reused to compromise other enterprise systems, potentially leading to remote code execution.

Attack surface

Reached over the network via the /c/router endpoint using getImageByPath; the CVSS vector shows no privileges or user interaction required. Any host that can reach the NAKIVO service can attempt the traversal.

Exploitation

CISA added this to KEV on 2025-03-19 with a 2025-04-09 remediation due date, and EPSS is 0.94356 (99.8th percentile), indicating active exploitation. A public proof-of-concept exploit is referenced by WatchTowr.

What to do

  • Upgrade NAKIVO Backup & Replication to 11.0.0.88174 or later immediately.
  • If patching is not possible, isolate the NAKIVO appliance from untrusted networks and restrict access to the management interface.
  • Rotate any credentials stored or used by PhysicalDiscovery and other NAKIVO components, since cleartext credentials may have been exposed.
  • Follow CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

Detection

  • Monitor HTTP requests to /c/router with getImageByPath parameters containing absolute paths or traversal sequences.
  • Alert on unexpected outbound connections or authentication attempts from the NAKIVO appliance using stored credentials.
  • Review file access logs on the appliance for reads of configuration or credential files outside expected paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-48248 to the Known Exploited Vulnerabilities catalog on 19 March 2025 as "NAKIVO Backup and Replication Absolute Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 April 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-48248 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-15850Nakivo backup \& replication director incorrect default permissions vulnerabilityInsecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interf…EPSS 0.52%5.5CVE-2025-39964Linux kernel af_alg race condition allows concurrent socket writesThe Linux kernel's af_alg crypto socket implementation did not prevent two concurrent writes to the same socket, allowing data to be interleaved unpr…KEVEPSS 1.00%analysed5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed7.0CVE-2025-62215Windows Kernel race condition and double free privilege escalationA race condition combined with a double free in the Windows Kernel lets a locally authenticated attacker corrupt kernel memory and elevate privileges…KEVEPSS 6.0%analysed7.8CVE-2025-38352Linux kernel POSIX CPU timer TOCTOU race enables local privilege escalationA time-of-check to time-of-use race exists in the Linux kernel between handle_posix_cpu_timers() and posix_cpu_timer_del(). When an exiting non-autor…KEVEPSS 1.3%analysed7.5CVE-2024-13161Ivanti Endpoint Manager absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 90%analysed7.5CVE-2024-13160Ivanti Endpoint Manager absolute path traversal information leakIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside …KEVEPSS 91%analysed7.5CVE-2024-13159Ivanti EPM absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-48248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.