Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.
Fixes

Solution

The vulnerability has been resolved by the Cires21 team in the latest software version of the affected products, which was released in the last week of November.


Workaround

No workaround given by the vendor.

History

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-06-02T15:05:45.346Z

Reserved: 2024-01-17T10:35:32.669Z

Link: CVE-2024-0642

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.621Z

cve-icon NVD

Status : Modified

Published: 2024-01-17T14:15:43.470

Modified: 2024-11-21T08:47:03.273

Link: CVE-2024-0642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.