>> All posts

CVE-2024-48248: NAKIVO Backup & Replication arbitrary file read, actively exploited

The short version: NAKIVO Backup & Replication has an absolute-path-traversal flaw (CVE-2024-48248) that lets an unauthenticated attacker read arbitrary files from the appliance. Because a backup product holds cleartext credentials for the systems it protects, an arbitrary file read here can hand an attacker the keys to much of the estate. It's in CISA's KEV catalog. If you run NAKIVO below 11.0.0.88174, patch and rotate. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated file read that discloses stored credentials (see below)
CVSS v3.1 (NVD)8.6 — High · AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS~94.08% · 99.84th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-04-09
Known exploited?Yes — exploited in the wild
Vulnerability typeCWE-36 absolute path traversal → arbitrary file read → disclosure of cleartext credentials
Requires authenticated session?No — unauthenticated
AffectedNAKIVO Backup & Replication before 11.0.0.88174
Fixed in11.0.0.88174 (and later)

What you need to know

NAKIVO Backup & Replication protects virtual, physical, and cloud workloads — which means it stores credentials for the systems it backs up. CVE-2024-48248 is an absolute path traversal reachable via the /c/router endpoint (the getImageByPath method) that lets an unauthenticated attacker read any file on the appliance.

The reason this is worse than a generic file read is what's on a backup server:

  • It's unauthenticated and network-reachable. One request, no login.
  • It reads any file — including the credential store. Backup products keep cleartext credentials for the assets they protect; reading those can extend the attack far beyond the appliance.
  • It's KEV-listed and actively exploited. Exposed, unpatched appliances were found and hit; public exploit tooling exists.

How serious we see it

High — and effectively worse when the files read are the stored credentials.

NVD's 8.6 reflects an unauthenticated, high-confidentiality read with scope change and no direct integrity or availability impact. We agree with the mechanics — this isn't code execution by itself — but the target makes it dangerous: an attacker who reads a backup appliance's credential store can pivot into the systems those backups protect. The bounded, reassuring part: it affects builds below 11.0.0.88174, the fix is published, and exposure is quick to determine — but patching doesn't un-leak a credential, so rotate.

Recommendations

  1. Patch now. Upgrade NAKIVO Backup & Replication to 11.0.0.88174 or later.
  2. Rotate credentials — don't skip this. Assume any credentials stored on the appliance were exposed; rotate them across the systems the backups protect.
  3. Hunt. Review logs for requests to /c/router and anomalous file-read activity around the exposure window.
  4. Reduce exposure. Keep the NAKIVO interface off the public internet; restrict management to trusted networks.
  5. Confirm your exposure first. Verify whether you run an internet-facing NAKIVO appliance and which build.

How BreachRisk sees it

BreachRisk discovers internet-facing NAKIVO panels from little more than your domain, fingerprints the version, and flags exposure tied to this KEV-listed, actively exploited flaw — surfaced at the top of your results because it's in KEV and because a credential-holding backup appliance deserves priority. We detect and prioritize the exposed, affected appliance; the outside-in view means it was already on your radar.

References

See your cyber risk, proven.