CVE-2024-53356 Details
Description
Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
A vulnerability exists in EasyVirt DCScope versions through 8.6.0 and CO2Scope versions through 1.3.0, due to a weak JSON Web Token (JWT) secret. The HMAC secret for generating tokens is hardcoded as 'somerandomaccesstoken', which is predictable and allows remote attackers to create valid JWTs. This could be exploited for privilege escalation by impersonating users with elevated rights.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-53356.md | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-53356.md | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| easyvirt co2scope | <= 1.3.0 |
CPE
Remediation
| |
| easyvirt dcscope | <= 8.6.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 23, 2025 | Initial Analysis | [email protected] |
| Feb 7, 2025 | CVE Modified | [email protected] |
| Feb 3, 2025 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | New CVE Received | [email protected] |