CVE-2024-55062: Easyvirt CO2SCOPE

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.

Affected products

  • Easyvirt CO2SCOPE: up to and including 1.3.0
  • Easyvirt Dcscope: up to and including 8.6.0

Published 2025-01-31. Last modified 2026-06-17.