Description
Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.
Published: 2024-01-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The vulnerability has been resolved by the Cires21 team in the latest software version of the affected products, which was released in the last week of November.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-16434 Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.
History

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cires21 Live Encoder
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-06-02T15:05:45.346Z

Reserved: 2024-01-17T10:35:32.669Z

Link: CVE-2024-0642

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.621Z

cve-icon NVD

Status : Modified

Published: 2024-01-17T14:15:43.470

Modified: 2024-11-21T08:47:03.273

Link: CVE-2024-0642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses