PT-2025-2960 · Easyvirt · Easyvirt Dcscope

Published

2025-01-31

·

Updated

2025-02-01

·

CVE-2024-53356

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EasyVirt DCScope versions 8.6.0 and earlier CO2Scope versions 1.3.0 and earlier
Description The issue allows remote attackers to generate JSON Web Tokens (JWTs) for privilege escalation due to a weak JWT secret. The HMAC secret used for generating tokens is hardcoded, posing a risk as attackers can use the predictable secret to create valid tokens, allowing access to important information and actions within the application.
Recommendations For EasyVirt DCScope versions 8.6.0 and earlier, update to a version that uses a secure HMAC secret. For CO2Scope versions 1.3.0 and earlier, update to a version that uses a secure HMAC secret. As a temporary workaround, consider restricting access to sensitive information and actions within the application to minimize the risk of exploitation.

Exploit

Fix

LPE

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-53356

Affected Products

Easyvirt Dcscope