The US government warns agencies to ensure that their backups are safe from Nakivo’s security problem


  • Nakivo corrected a high severity flaw in November 2024
  • However, Cisa has now added it to Kev, signaling abuse in the wild
  • The bug can lead to the execution of the remote code

The American Cybersecurity and Infrastructure Safety Agency (CISA) added a Nakivo bug to its known catalog of exploited vulnerabilities (KEV), signaling abuse in the inhabitants and giving government agencies a deadline to apply the provided patch.

The bug in question is followed as CVE-2024-48248. It is a vulnerability of absolute path crossing affecting the backup and replication software, in the versions before 11.0.0.88174.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top