📦 Dcscope

by Easyvirt

🔍 What is Dcscope?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57587

CRITICAL CVSS 9.1 Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope and CO2Scope allow remote unauthenticated attackers to execute arbitrary SQL commands via login parameters. This affects all users running vu...

CVE-2024-55062

CRITICAL CVSS 9.8 Jan 31, 2025

This is a critical code injection vulnerability in EasyVirt DCScope and CO2Scope that allows remote unauthenticated attackers to execute arbitrary code via the /api/license/sendlicense/ endpoint. Atta...

CVE-2024-53356

CRITICAL CVSS 9.8 Jan 31, 2025

This vulnerability allows remote attackers to generate valid JWT tokens using a hardcoded weak secret, enabling privilege escalation in affected EasyVirt products. Attackers can access sensitive infor...

CVE-2024-53355

HIGH CVSS 8.8 Jan 31, 2025

This CVE describes multiple incorrect access control vulnerabilities in EasyVirt DCScope and CO2Scope management software. Remote authenticated attackers with low privileges can perform administrative...

CVE-2024-53357

HIGH CVSS 7.5 Jan 31, 2025

Multiple SQL injection vulnerabilities in EasyVirt DCScope and CO2Scope allow authenticated attackers with low privileges to manipulate user, group, and role management functions. Attackers can add ad...