Nakivo develops backup and disaster-recovery software, with its vulnerability exposure centered on the Backup & Replication Director and Transporter products and characterized by access-control and authentication weaknesses including absolute path traversal, incorrect default permissions, and missing authentication for critical functions. These patterns reflect the administrative and file-handling responsibilities of backup appliances; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nakivo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48248HIGH NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the | Mar 4, 2025 | 8.6 | 97 | YES | YES |
CVE-2020-15851CRITICAL Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller confi | Sep 24, 2020 | 9.8 | 29 | NO | NO |
CVE-2025-32406HIGH An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response. | Apr 8, 2025 | 8.6 | 24 | NO | NO |
CVE-2020-15850HIGH Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. T | Sep 24, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nakivo.
Media articles that mention a CVE ID that affects a product developed by Nakivo — matched by CVE ID, not by vendor name.