CVE-2024-53356
Last modified
CVE-2024-53356 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JWT for privilege escalation. The HMAC secret used for generating tokens is hardcoded as "somerandomaccesstoken". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Easyvirt | Co2scope | <= 1.3.0 |
| Easyvirt | Dcscope | <= 8.6.0 |
References
- https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-53356.mdExploit, Third Party Advisory
- https://github.com/Elymaro/CVE/blob/main/EasyVirt/CVE-2024-53356.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-53356?
How severe is CVE-2024-53356?
How do I fix CVE-2024-53356?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-53349Insecure permissions in kuadrant v0.11.3 allow attackers to …7.4
- CVE-2024-5335The Ultimate Store Kit Elementor Addons, Woocommerce Builder…9.8
- CVE-2024-53350Insecure permissions in kubeslice v1.3.1 allow attackers to …7.4
- CVE-2024-53351Insecure permissions in pipecd v0.49 allow attackers to gain…9.8
- CVE-2024-53354Multiple SQL injection vulnerabilities in EasyVirt DCScope <…6.5
- CVE-2024-53355Multiple incorrect access control issues in EasyVirt DCScope…8.8
- CVE-2024-53357Multiple SQL injection vulnerabilities in EasyVirt DCScope <…7.5
- CVE-2024-53359An issue in Zalo v23.09.01 allows attackers to obtain sensit…7.5
- CVE-2024-5336A vulnerability has been found in Ruijie RG-UAC up to 202405…7.2
- CVE-2024-53364A SQL injection vulnerability was found in PHPGURUKUL Vehicl…5.4
- CVE-2024-53365A stored cross-site scripting (XSS) vulnerability was identi…5.4
- CVE-2024-5337A vulnerability was found in Ruijie RG-UAC up to 20240516 an…7.2
Are you affected by CVE-2024-53356?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
