CVE-2024-26291
Severity CVSS v4.0:
HIGH
Type:
CWE-285
Improper Authorization
Publication date:
14/07/2025
Last modified:
15/07/2025
Description
An Unauthenticated Arbitrary File Read vulnerability affects the<br />
Agent when installed on a system. The parameter filename does not validate the<br />
path thus allowing users to read arbitrary files. As<br />
the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM)<br />
by default attackers are able to obtain sensitive information.<br />
<br />
This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH



