CVE-2024-55062

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 31, 2025
Updated: Feb 11, 2025
CWE ID 77

Summary

CVE-2024-55062 is a code injection vulnerability affecting EasyVirt DCScope versions up to 8.6.0 and CO2Scope versions up to 1.3.0. This weakness permits unauthenticated attackers to inject and execute arbitrary code through the /api/license/sendlicense/ endpoint. Successful exploitation of this vulnerability could lead to significant security implications, including system compromise and data theft. It is recommended that affected users upgrade to the latest versions of these products to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share