First published: Tue Mar 04 2025(Updated: )
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nakivo Backup & Replication | <11.0.0.88174 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48248 is considered a high-severity vulnerability due to its potential for remote code execution.
To mitigate CVE-2024-48248, ensure you update NAKIVO Backup & Replication to version 11.0.0.88174 or later.
CVE-2024-48248 is classified as an absolute path traversal vulnerability.
CVE-2024-48248 may allow an attacker to read arbitrary files, potentially leading to remote code execution.
CVE-2024-48248 affects NAKIVO Backup & Replication versions prior to 11.0.0.88174.