{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-18T22:33:46.491","vulnerabilities":[{"cve":{"id":"CVE-2020-15850","sourceIdentifier":"cve@mitre.org","published":"2020-09-24T21:15:15.513","lastModified":"2024-11-21T05:06:18.570","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value is readable."},{"lang":"es","value":"Unos permisos no seguros en Nakivo Backup &amp; Replication Director versión 9.4.0.r43656 en Linux, permiten a usuarios locales acceder a la interfaz web de Nakivo Director y alcanzar privilegios root.&#xa0;Esto ocurre porque la base de datos que contiene los usuarios de la aplicación web y el valor secreto de recuperación de contraseña es legible."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nakivo:backup_\\&_replication_director:9.4.0.r43656:*:*:*:*:*:*:*","matchCriteriaId":"14FCC7C5-2E4D-4952-AF8A-86D8ABA72C72"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","matchCriteriaId":"703AF700-7A70-47E2-BC3A-7FD03B3CA9C1"}]}]}],"references":[{"url":"https://helpcenter.nakivo.com/display/RN/v10.3+Release+Notes","source":"cve@mitre.org","tags":["Release Notes","Vendor Advisory"]},{"url":"https://labs.f-secure.com/advisories/nakivo-backup-and-replication-multiple-vulnerabilities","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://helpcenter.nakivo.com/display/RN/v10.3+Release+Notes","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"]},{"url":"https://labs.f-secure.com/advisories/nakivo-backup-and-replication-multiple-vulnerabilities","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}