CVE-2024-53355
Multiple incorrect access control issues in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers, with low privileges, to (1) add an admin user via the /api/user/addalias route.
(2) modifiy a user via the /api/user/updatealias route.
(4) delete users via the /api/user/delalias route.
(4) get users via the /api/user/aliases route.
(5) add a root group via the /api/user/adduser route.
(6) modifiy a group via the /api/user/updateuser route.
(7) delete a group via the /api/user/deluser route.
(8) get groups via the /api/user/users route.
(9) add an admin role via the /api/user/addrole route.
(10) modifiy a role via the /api/user/updaterole route.
(11) delete a role via the /api/user/delrole route.
(12) get roles via the /api/user/roles route.
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
ATT&CK techniques
1Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
▤ Build a SIEM detection for these techniques