Home

Description

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before 2024.6.0; Avid NEXIS F-series: before 2024.6.0; Avid NEXIS PRO+: before 2024.6.0; System Director Appliance (SDA+): before 2024.6.0.

PUBLISHED Reserved 2024-02-16 | Published 2025-03-12 | Updated 2025-04-15 | Assigner ENISA




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 2024.6.0
affected

Default status
unaffected

Any version before 2024.6.0
affected

Default status
unaffected

Any version before 2024.6.0
affected

Default status
unaffected

Any version before 2024.6.0
affected

Credits

DriveByte finder

References

raeph123.github.io/...Agent_Multiple_Vulnerabilities_en.html

www.drive-byte.de/...id-nexis-agent-multiple-vulnerabilities third-party-advisory

kb.avid.com/pkb/articles/troubleshooting/en239659 vendor-advisory

cve.org (CVE-2024-26290)

nvd.nist.gov (CVE-2024-26290)