theinfosecnews

CVE-2024-48248

CISA KEV

Published March 19, 2025 · Updated April 3, 2026

high
Official Description+

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

Affected Products

VendorProduct
NAKIVOBackup and Replication

Patch Status

Patch by 2025-04-09

Recommended Actions

  1. Check if your systems use any of the affected products listed above.
  2. Apply vendor patches immediately if available.
  3. This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
  4. Monitor vendor advisories for updates and additional mitigations.
  5. Review logs for indicators of compromise related to CVE-2024-48248.