PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 22, 2026

Avid NEXIS Agent - Arbitrary File Read

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
8.7
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain sensitive information. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Avid NEXIS E-seriesby Avid
AFFECTED< 2025.5.1SAFE ✓≥ 2025.5.1
Avid NEXIS F-seriesby Avid
AFFECTED< 2025.5.1SAFE ✓≥ 2025.5.1
Avid NEXIS PRO+by Avid
AFFECTED< 2025.5.1SAFE ✓≥ 2025.5.1
System Director Appliance (SDA+)by Avid
AFFECTED< 2025.5.1SAFE ✓≥ 2025.5.1
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.