CVE-2020-15851: NAKIVO Backup & Replication Transporter

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible to create or delete backup repositories.

Affected products

  • NAKIVO Backup & Replication Transporter: version 9.4.0.r43656 only

Published 2020-09-24. Last modified 2026-06-17.