PT-2025-11126 · Avid · Avid Nexis E-Series+2
Drivebyte
+1
·
Published
2025-03-12
·
Updated
2025-03-14
·
CVE-2024-26290
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Avid NEXIS E-series versions prior to 2024.6.0
Avid NEXIS F-series versions prior to 2024.6.0
Avid NEXIS PRO+ versions prior to 2024.6.0
System Director Appliance (SDA+) versions prior to 2024.6.0
Description:
The issue is related to an Improper Input Validation vulnerability in Avid products on Linux, allowing code execution on the underlying operating system with root permissions.
Recommendations:
Update Avid NEXIS E-series to version 2024.6.0 or later
Update Avid NEXIS F-series to version 2024.6.0 or later
Update Avid NEXIS PRO+ to version 2024.6.0 or later
Update System Director Appliance (SDA+) to version 2024.6.0 or later
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avid Nexis E-Series
Avid Nexis Pro+
System Director Appliance