VDB

CVE-2024-48248

CVE-2024-48248 PUBLISHED KEV CVSS 8.600000381469727 HIGH

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

EPSS 94.36% · 99.8th percentile

Risk Scores

CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score
94.36%
99.8th percentile

Affected Products

VendorProductVersions
nakivobackup_\&_replication_director0, 0, 0
NAKIVOBackup & Replication Director0, 0
QnapNAKIVO Backup & Replication

Timeline

  • Feb 26, 2025 PoC Published
  • Feb 26, 2025 PoC Published
  • Feb 26, 2025 PoC Published
  • Feb 26, 2025 VulnCheck XDB Entry
  • Feb 26, 2025 PoC Published
  • Feb 26, 2025 PoC Published
  • Feb 27, 2025 PoC Published
  • Feb 27, 2025 PoC Published
  • Feb 27, 2025 PoC Published
  • Feb 27, 2025 PoC Published
  • Feb 27, 2025 PoC Published
  • Feb 27, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›