# CVE-2024-26293

## Summary

- **CVE ID:** CVE-2024-26293
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1395
- **Published:** Jul 14, 2025
- **Last Modified:** Mar 13, 2026

## Description

The Avid Nexis Agent uses a vulnerable gSOAP
version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability.
This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

## Affected Products

- Avid — Avid NEXIS E-series (0)
- Avid — Avid NEXIS F-series (0)
- Avid — Avid NEXIS PRO+ (0)
- Avid — System Director Appliance (SDA+) (0)

## References

- [CNA](https://resources.avid.com/SupportFiles/attach/AvidNEXIS/AvidNEXIS_2025_5_1_ReadMe.pdf)
- [CNA](https://raeph123.github.io/BlogPosts/Avid_Nexis/Advisory_Avid_Nexus_Agent_Multiple_Vulnerabilities_en.html)
- [CNA](https://www.genivia.com/changelog.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 28.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._