CVE-2020-15850

HIGH

Nakivo Backup & Replication Director 9.4.0.r43656 - Privilege Escalation via Insecure Database Permissions

Title source: llm
STIX 2.1

Description

Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://helpcenter.nakivo.com/display/RN/v10.3+Release+Notes

Scores

CVSS v3 7.8
EPSS 0.0052
EPSS Percentile 40.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
nakivo/backup_\&_replication_director 9.4.0.r43656
Published Sep 24, 2020
Tracked Since Feb 18, 2026