Avid NEXIS E-series等都是美国Avid公司的一款虚拟化存储平台。 Avid多款产品存在安全漏洞,该漏洞源于未验证文件名参数路径,可能导致任意文件读取攻击。以下产品及版本受到影响:Avid NEXIS E-series、Avid NEXIS F-series、Avid NEXIS PRO+和System Director Appliance (SDA+) 2025.5.1之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Avid | Avid NEXIS E-series | 0 ~ 2025.5.1 | - |
|
| Avid | Avid NEXIS F-series | 0 ~ 2025.5.1 | - |
|
| Avid | Avid NEXIS PRO+ | 0 ~ 2025.5.1 | - |
|
| Avid | System Director Appliance (SDA+) | 0 ~ 2025.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Avid NEXIS E-series, F-series, PRO+, and System Director Appliance (SDA+) before 2025.5.1 contain an unauthenticated arbitrary file read caused by improper validation of the filename parameter, letting unauthenticated attackers read sensitive files, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-26291.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-26292 | Authenticated Arbitrary File Deletion affecting Avid NEXIS | |
| CVE-2024-26293 | Unauthenticated Path Traversal affecting Avid NEXIS |
No comments yet