CVE-2024-26291
Authenticated Arbitrary File Read affecting Avid NEXIS
Record summary
CVE-2024-26291 has a selected CVSS score of 8.7 (high); EIP currently links 1 Nuclei template.
Description
An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain sensitive information. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 14, 2025 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Avid NEXIS E-seriesBrowse Avid / Avid NEXIS E-seriesDefault status: unaffected | CVE List | Before 2025.5.1 | affected |
Avid NEXIS F-seriesBrowse Avid / Avid NEXIS F-seriesDefault status: unaffected | CVE List | Before 2025.5.1 | affected |
Avid NEXIS PRO+Browse Avid / Avid NEXIS PRO+Default status: unaffected | CVE List | Before 2025.5.1 | affected |
System Director Appliance (SDA+)Browse Avid / System Director Appliance (SDA+)Default status: unaffected | CVE List | Before 2025.5.1 | affected |
Nuclei templates
1ProjectDiscoveryHIGHAvid NEXIS Agent - Arbitrary File ReadCVSS 7.5
Avid NEXIS E-series, F-series, PRO+, and System Director Appliance (SDA+) before 2025.5.1 contain an unauthenticated arbitrary file read caused by improper validation of the filename parameter, letting unauthenticated attackers read sensitive files, exploit requires no authentication.
Impact
Unauthenticated attackers can read sensitive files with highest privileges, potentially exposing critical information.
Remediation
Upgrade to Avid NEXIS version 2025.5.1 or later.
Source: ProjectDiscovery