Vulnerability Details CVE-2024-48248
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.934
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 8.6
Proposed Action
NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.
Ransomware Campaign
Unknown
Products affected by CVE-2024-48248
-
cpe:2.3:a:nakivo:backup_&_replication_director:9.4.0.r43656