SimplyLive
2.1 2.0 English German
2.1 2.0 English German

Risk Context

Intended Purpose

SimplyLive products are designed to be used for Live Video Production workflows, in the professional broadcast market, with a particular attention to Live Sports. The product was designed to run in managed media networks. SimplyLive should be deployed to customer environments owned and operated by technology professionals able to limit and control both physical and digital access to critical systems. Open access to the public internet only possible, via an air gapped DMZ or managed firewall.

Within the managed media network, we assume ports are open between server and clients running SimplyLive software.

For further information on our best practices and a list of ports used by application, please request a copy of the latest version of the SimplyLive IT&S Guidelines.

Reasonably Foreseeable Use

In addition to the intended purpose, the manufacturer reasonably foresees that users may:

  • Allow access to media content from devices outside of the managed media network via a limited set of managed ports and sender/receiver IP addressed for applications such as:

    • SRT for video transport from disparate geographic locations, over managed or public wide area network connections.

    • TS RTP for video transport from disparate geographic locations, over managed or public wide area network connections.

    • TS UDP for video transport from disparate geographic locations, over managed or public wide area network connections.

    • RTMP for video transport from disparate geographic locations, over managed or public wide area network connections.

    • NDI for video transport from disparate geographic locations, over managed or public wide area network connections.

  • For remote workflows, where the server and end users client device are located in diverse geographical locations, users are likely to employ the use of NiceDCV for remote desktop mirroring.

  • For remote support:

    • We expect the customer to provide system logs and be able to follow guidelines for retrieval then share them with support via the secure Riedel support portal.

    • VPN access for remote support or management from the customers support teams or Riedel customer success. The VPN service should be provided and operated by the customer, providing Riedel support teams with a VPN Client.

Foreseeable Misuse

SimplyLive must not be used in safety-critical or high-risk environments where system failure could cause harm or major damage.

Prohibited uses include: 

  • Physical Security Risks:
    SimplyLive products deployed in environments that do not provide adequate physical security controls may be exposed to unauthorized physical access, tampering, theft, or compromise of sensitive data and system integrity. Examples include, but are not limited to:

    • Installation within facilities where access to technical operational areas, machine rooms, or equipment racks is not restricted through controlled entry mechanisms (for example: security passes, access cards, or other authorized personnel controls).

    • Deployment within fly-away systems for portable production units or temporary installations located at venues where access to equipment is open to anyone and is not limited to designated technical with access continuously monitored and controlled by security personnel.

    • Installation within Outside Broadcast (OB) vehicles where access to server hardware is not restricted to authorized personnel and physical security controls and limitations are absent or insufficient.

  • Network Security Risks:
    SimplyLive products connected to networks that are not adequately segmented, secured, or controlled may be exposed to unauthorized access, malicious activity, lateral movement, or data interception. Examples include, but are not limited to:

    • Client systems, servers, or both connected to a single IT network for all company equipment including personal or corporate personal computers or mobile devices, where unrestricted communication is permitted between any devices, services, or ports without appropriate access control mechanisms, firewall policies, or network segmentation.

    • SimplyLive systems connected to networks that provide direct or indirect connectivity to devices with unrestricted internet access, increasing the potential attack surface and risk of compromise.

    • Deployment on shared, public, or otherwise untrusted networks where unauthorized users or devices may gain network-level access to SimplyLive services, management interfaces, or data traffic.

  • Alternative Industry Verticals and Market Segments:
    SimplyLive has been designed specifically for use in the Media Technology markets, specifically Broadcast and Professional AV. SimplyLive has not been designed nor do we advise it to be used in:

    • Aviation, rail, and maritime safety systems (e.g., review or monitoring of audio and video recording and playback).

    • Medical life-critical systems (e.g. remote viewing for surgical control).

    • Any system where system failure could directly cause injury, death, or major environmental/industrial damage.


Reporting a Security Vulnerability

Riedel Communications is committed to the security of its products. If you believe you have identified a security vulnerability in this product, please report it to us at https://my.riedel.net/vulnerability. There you'll find guidance on how to submit a report, what details to include so we can investigate promptly, and what to expect from us once a report is received. We ask that you report suspected vulnerabilities in good faith and allow us a reasonable opportunity to assess and address the issue before any public disclosure.

The same page lists known and publicly disclosed vulnerabilities affecting Riedel products, along with available guidance, workarounds, and security updates. We recommend checking this page periodically and subscribing to any available notifications to stay informed of security issues relevant to your equipment.