Nakivo Fixes Critical Flaw in Backup & Replication Tool
ID: cb102d96-497a-5f0f-8d71-f21145889dc6
STIX ID: report--cb102d96-497a-5f0f-8d71-f21145889dc6
Feed Name: Dark Reading
Nakivo patched a critical unauthenticated arbitrary file read vulnerability (CVE-2024-48248) in its Backup & Replication product after watchTowr discovered and reported it; the bug lets an attacker retrieve any file (including backups and credentials) with a single crafted HTTP request, was trivial to find on the Internet using search engines, and a PoC/tool was published—presenting a high risk to organizations that rely on Nakivo backups, especially given ransomware actors target backup solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
