Unauthenticated Arbitrary File Read Vulnerability in Avid NEXIS Products
CVE-2024-26291

8.7HIGH

What is CVE-2024-26291?

A vulnerability exists in the Avid NEXIS products that allows an attacker to read arbitrary files without authentication. The flaw is in the handling of the 'filename' parameter, which fails to validate paths correctly. This oversight can enable unauthorized users to access sensitive files, potentially exposing critical information. Because the affected applications often run with elevated privileges, the impact of this vulnerability can be severe, affecting the security posture of systems utilizing Avid NEXIS solutions.

Affected Version(s)

Avid NEXIS E-series Linux 0 < 2025.5.1

Avid NEXIS F-series Linux 0 < 2025.5.1

Avid NEXIS PRO+ Linux 0 < 2025.5.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DriveByte
CERT-Bund
.
CVE-2024-26291 : Unauthenticated Arbitrary File Read Vulnerability in Avid NEXIS Products