Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46063 | A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function. |
| Link | Providers |
|---|---|
| https://zuso.ai/advisory/za-2024-11 |
|
Fri, 06 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gss
Gss iota C.ai |
|
| CPEs | cpe:2.3:a:gss:iota_c.ai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gss
Gss iota C.ai |
|
| Metrics |
cvssV3_1
|
Wed, 27 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Galaxy Software Services Corporation
Galaxy Software Services Corporation iota C.ai Conversational Platform |
|
| CPEs | cpe:2.3:a:galaxy_software_services_corporation:iota_c.ai_conversational_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Galaxy Software Services Corporation
Galaxy Software Services Corporation iota C.ai Conversational Platform |
|
| Metrics |
ssvc
|
Wed, 27 Nov 2024 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function. | |
| Title | iota C.ai Conversational Platform - Improper Verification of Cryptographic Signature | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2024-11-27T14:46:28.815Z
Reserved: 2024-11-18T08:24:35.610Z
Link: CVE-2024-52958
Updated: 2024-11-27T14:46:08.758Z
Status : Analyzed
Published: 2024-11-27T06:15:18.590
Modified: 2026-03-06T18:42:54.940
Link: CVE-2024-52958
No data.
OpenCVE Enrichment
No data.
EUVD