← Back to browse · API

CVE-2024-48248

Severity
HIGH
CVSS
8.6
EPSS
0.94265
Risk score
57.99
CISA KEV
Yes
PoC
No
Published
2025-03-04
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-54120, GHSA-8J8G-6GW9-RJRF
Products
NAKIVO:Backup & Replication Director 0 <11.0.0.88174, NAKIVO:Backup and Replication
Sources
cisa.gov CVE-2024-48248
euvd EUVD-2024-54120

Description

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

References