LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-48248: NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 19, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 9, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-48248 to its Known Exploited Vulnerabilities catalog on Mar 19, 2025, with a federal patch deadline of Apr 9, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

CVE-2024-48248 is an absolute path traversal vulnerability in NAKIVO Backup and Replication. It allows an attacker to read arbitrary files on the system hosting the product. Backup and replication platforms often hold credentials, configuration data, and copies of production systems, so unauthorized file access can expose sensitive operational and business information. Defenders should treat this as a high-priority review item for any environment running the software.

Public detail is limited to the CISA summary and the stated weakness class. Confirm exact impact, affected releases, and exploitation prerequisites against the vendor advisory before acting.

How it works

The flaw is classified as CWE-36, Absolute Path Traversal. In this class of weakness, the application fails to properly restrict file-system paths supplied by a user or remote request. An attacker who can reach the vulnerable interface can supply an absolute path that points outside the intended directory, causing the application to open and return the contents of files that should remain inaccessible.

Because the product is a backup and replication solution, successful abuse can yield configuration files, credential stores, logs, or other data that the service account can read. No public exploit code or precise request format is provided in the available facts; treat any claimed proof-of-concept as unverified until matched against the vendor’s technical description. The core risk remains unauthorized disclosure of files the process can access.

Am I affected? How to find it in your systems

NAKIVO Backup and Replication is typically deployed as a dedicated appliance, virtual machine, or installed service that manages backups of virtual machines, physical servers, or cloud workloads. Inventory steps include:

Once instances are located, compare the installed version and build against the list of fixed releases published by the vendor. Also note whether the management interface is reachable from untrusted networks. Log sources that may indicate exploitation include unexpected file-open events by the NAKIVO service account, anomalous HTTP or API requests containing absolute path strings, and sudden spikes in read activity against system directories outside the product’s normal working set. Correlate these with authentication logs for the management console.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2024-48248. Follow the installation and verification steps published in the official advisory. After patching, restart the affected services and confirm the new version string.

Additional hardening for this class of flaw includes:

CISA guidance further directs organizations to apply mitigations per vendor instructions, follow BOD 22-01 for any cloud-hosted instances, or discontinue use if mitigations cannot be implemented.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls:

Document every temporary control and schedule the permanent patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited path-traversal flaws can lead to data breaches when sensitive files are read. Although ransomware use of this specific CVE is not documented, any confirmed unauthorized file access should trigger incident-response procedures: isolate the host, preserve logs, and assess which files may have been disclosed. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether related credentials or personal information have already appeared in public dumps. Continue monitoring for secondary use of any material that may have been obtained.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNAKIVO · Backup and Replication
WeaknessCWE-36
Added to CISA KEVMar 19, 2025
Federal patch deadlineApr 9, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities