Vulnerabilities > CVE-2024-48248 - Unspecified vulnerability in Nakivo Backup & Replication Director 9.4.0.R43656

047910
CVSS 8.6 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
nakivo

Summary

NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).

Vulnerable Configurations

Part Description Count
Application
Nakivo
1