The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to U.S. federal agencies regarding a high-severity vulnerability in NAKIVO Backup & Replication software. The flaw, identified as CVE-2024-48248, allows unauthenticated attackers to read arbitrary files on vulnerable systems through an absolute path traversal vulnerability.
NAKIVO, a U.S.-based backup and ransomware recovery software vendor, quietly patched the security issue in November with the release of version 11.0.0.88174. The vulnerability was discovered by cybersecurity firm watchTowr nearly two months before the patch was released.
“Exploiting this vulnerability could expose sensitive data, including configuration files, backups, and credentials, potentially leading to data breaches or further security compromises,” NAKIVO explained. WatchTowr added that the impact “goes beyond merely stealing backups — to essentially unlocking entire infrastructure environments.”
In February, watchTowr released a proof-of-concept tool for CVE-2024-48248, described as both a “detection artifact generator” and “an unofficial NAKIVO customer support tool.”
## Active Exploitation Confirmed
CISA has now added this vulnerability to its Known Exploited Vulnerabilities catalog, confirming it is being actively exploited in the wild. Federal Civilian Executive Branch agencies have until April 9th to secure their systems against attacks, as required by Binding Operational Directive 22-01.
“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA stated.
While the directive only applies to federal agencies, all organizations using NAKIVO products are strongly advised to prioritize patching immediately to prevent attacks.
NAKIVO serves over 30,000 active customers across 183 countries, including major corporations like Honda, Cisco, Coca-Cola, and Siemens, through a network of more than 8,000 partners worldwide.
