CVE detail
CVE-2020-15850 — CVE-2020-15850
Published 2020-09-24 · Modified 2026-06-17 · Vendor nakivo · Product backup_\&_replication_director · Source nvd
HIGH
severity
CVSS-derived band
0.0052
EPSS probability
exploitation probability, 30d
42.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References