CVE-2024-26290 Details
Description
Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before 2024.6.0; Avid NEXIS F-series: before 2024.6.0; Avid NEXIS PRO+: before 2024.6.0; System Director Appliance (SDA+): before 2024.6.0.
A vulnerability allowing remote code execution on the underlying operating system with root permissions has been identified in multiple Avid NEXIS products, including the E-series, F-series, PRO+, and the System Director Appliance (SDA+), all running on Linux. This vulnerability arises from improper input validation in the Avid NEXIS Web Agent, which allows authenticated users to execute system commands directed to specific IP addresses without proper validation. As a result, an authenticated attacker could exploit this flaw to execute arbitrary commands on the target machine.
Users are advised to upgrade to Avid NEXIS version 2024.6.0, available for download since June 18, 2024. If an immediate upgrade is not possible, Avid recommends configuring a firewall rule to whitelist access to the Storage Manager Agent on port 5015.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 12, 2025CISA-ADP
Assessed Mar 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.avid.com/pkb/articles/troubleshooting/en239659 | ENISA | AdvisoryRemedyVendor |
| https://www.drive-byte.de/en/blog/avid-nexis-agent-multiple-vulnerabilities | ENISA | Broken Link |
| https://raeph123.github.io/BlogPosts/Avid_Nexis/Advisory_Avid_Nexus_Agent_Multiple_Vulnerabilities_en.html | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | ENISA |
Affected Products
| Product | Versions |
|---|---|
| Avid NEXIS E-series | < 2024.6.0 (semver) |
CPE
Remediation
| |
| Avid NEXIS F-series | < 2024.6.0 (semver) |
CPE
Remediation
| |
| Avid NEXIS PRO+ | < 2024.6.0 (semver) |
CPE
Remediation
| |
| Avid System Director Appliance | < 2024.6.0 (semver) |
CPE
Remediation
| |
| Avid NEXIS Agent | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | CVE Modified | CVE |
| Mar 12, 2025 | New CVE Received | ENISA |
Volerion