CVE-2024-26292

An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de eliminación arbitraria de archivos autenticada permite a un atacante eliminar archivos críticos. Este problema afecta a Avid NEXIS serie E (anterior a 2025.5.1); Avid NEXIS serie F (anterior a 2025.5.1); Avid NEXIS PRO+ (anterior a 2025.5.1); System Director Appliance (SDA+): anterior a 2025.5.1.

14 Jul 2025, 10:15

Type Values Removed Values Added
Summary (en) The Application is vulnerable to an authenticated Arbitrary File Deletion. This affects the Agent installed on Linux and Windows alike. As the application runs with highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers may use the vulnerability to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1. (en) An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

14 Jul 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-14 09:15

Updated : 2025-07-15 13:14


NVD link : CVE-2024-26292

Mitre link : CVE-2024-26292

CVE.ORG link : CVE-2024-26292


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')