TROYANOSYVIRUS
Back to CVEs

CVE-2024-53356

CRITICAL
9.8

Description

Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published1/31/2025
Last Modified5/23/2025
Sourcenvd
Honeypot Sightings0

Affected Products

easyvirt:co2scopeeasyvirt:dcscope

Weaknesses (CWE)

CWE-798

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.