We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-26290

Authenticated Remote Command Injection affecting Avid NEXIS



Description

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before 2024.6.0; Avid NEXIS F-series: before 2024.6.0; Avid NEXIS PRO+: before 2024.6.0; System Director Appliance (SDA+): before 2024.6.0.

Reserved 2024-02-16 | Published 2025-03-12 | Updated 2025-03-12 | Assigner ENISA


HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 2024.6.0
affected

Default status
unaffected

Any version before 2024.6.0
affected

Default status
unaffected

Any version before 2024.6.0
affected

Default status
unaffected

Any version before 2024.6.0
affected

Credits

DriveByte finder

References

www.drive-byte.de/...id-nexis-agent-multiple-vulnerabilities third-party-advisory

kb.avid.com/pkb/articles/troubleshooting/en239659 vendor-advisory

cve.org (CVE-2024-26290)

nvd.nist.gov (CVE-2024-26290)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-26290

Support options

Helpdesk Chat, Email, Knowledgebase