PT-2025-11126 · Avid · Avid Nexis E-Series+2

Drivebyte

+1

·

Published

2025-03-12

·

Updated

2025-03-14

·

CVE-2024-26290

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Avid NEXIS E-series versions prior to 2024.6.0 Avid NEXIS F-series versions prior to 2024.6.0 Avid NEXIS PRO+ versions prior to 2024.6.0 System Director Appliance (SDA+) versions prior to 2024.6.0
Description: The issue is related to an Improper Input Validation vulnerability in Avid products on Linux, allowing code execution on the underlying operating system with root permissions.
Recommendations: Update Avid NEXIS E-series to version 2024.6.0 or later Update Avid NEXIS F-series to version 2024.6.0 or later Update Avid NEXIS PRO+ to version 2024.6.0 or later Update System Director Appliance (SDA+) to version 2024.6.0 or later

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-26290

Affected Products

Avid Nexis E-Series
Avid Nexis Pro+
System Director Appliance