Record summary

CVE-2024-26291 has a selected CVSS score of 8.7 (high); EIP currently links 1 Nuclei template.

Description

An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain sensitive information. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 14, 2025 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 2025.5.1affected

Default status: unaffected

CVE ListBefore 2025.5.1affected

Default status: unaffected

CVE ListBefore 2025.5.1affected

System Director Appliance (SDA+)

Browse Avid / System Director Appliance (SDA+)

Default status: unaffected

CVE ListBefore 2025.5.1affected

Nuclei templates

1
ProjectDiscoveryHIGHAvid NEXIS Agent - Arbitrary File ReadCVSS 7.5

Avid NEXIS E-series, F-series, PRO+, and System Director Appliance (SDA+) before 2025.5.1 contain an unauthenticated arbitrary file read caused by improper validation of the filename parameter, letting unauthenticated attackers read sensitive files, exploit requires no authentication.

Impact

Unauthenticated attackers can read sensitive files with highest privileges, potentially exposing critical information.

Remediation

Upgrade to Avid NEXIS version 2025.5.1 or later.

WeaknessesCWE-285
AuthorsDhiyaneshDK
Template tagscvecve2024avidnexislfifile-readgsoap
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
FOFA: body="Avid Nexis"

Source: ProjectDiscovery

References

3