CVE-2025-32406
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
08/04/2025
Last modified:
15/04/2026
Description
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH



