CVE-2024-11308: Trcore Dvc

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

Affected products

  • Trcore Dvc: from 6.0, before 6.4 (fixed in 6.4)

Published 2024-11-18. Last modified 2026-06-17.