{"id":"CVE-2024-48248","title":"NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…","summary":"NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-36"],"vendor":"nakivo","product":"backup_&_replication_director","affected":["backup_&_replication_director < 11.0.0.88174"],"patched":["backup_&_replication_director 11.0.0.88174"],"published":"2025-03-04","updated":"2026-09-24","sourceUpdated":"2026-09-24T13:10:00.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-48248","references":[{"url":"https://helpcenter.nakivo.com/Release-Notes/Content/Release-Notes.htm","label":"cve@mitre.org"},{"url":"https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/","label":"cve@mitre.org"},{"url":"https://github.com/watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248/?ref=labs.watchtowr.com","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-48248","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.94356,"epssPercentile":0.99849,"kev":true,"kevDateAdded":"2025-03-19","kevDueDate":"2025-04-09","kevRansomware":false,"exploited":true,"exploits":{"github":1,"githubRepos":["https://github.com/watchtowrlabs/nakivo-arbitrary-file-read-poc-CVE-2024-48248"],"nuclei":["CVE-2024-48248"],"checkedAt":"2026-09-24T13:43:59.530Z"},"exploitAvailable":true,"ingestedAt":"2026-09-24T13:43:25.654Z","slug":"CVE-2024-48248","body":"## Overview\n\nNAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).\n\n## Affected\n\n- `backup_&_replication_director < 11.0.0.88174`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `backup_&_replication_director 11.0.0.88174`","depth":"abyssal","depthScore":91,"depthScoreParts":{"impact":47.3,"likelihood":18.9,"exploitation":25,"ransomware":0},"changes":[]}