Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload different file extensions without any restrictions, resulting in a full system compromise.
Fixes

Solution

The vulnerability has been resolved by the Cires21 team in the latest software version of the affected products, which was released in the last week of November.


Workaround

No workaround given by the vendor.

History

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-06-02T15:05:37.586Z

Reserved: 2024-01-17T10:35:34.863Z

Link: CVE-2024-0643

cve-icon Vulnrichment

Updated: 2024-08-01T18:11:35.744Z

cve-icon NVD

Status : Modified

Published: 2024-01-17T14:15:43.920

Modified: 2024-11-21T08:47:03.413

Link: CVE-2024-0643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.