Cyber Resilience

CVE-2024-6890

Exposed Creds in Journyx 11.5.4

Public PoCExposed Creds
Published
07 August 2024
Modified
21 November 2024
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0072 51th percentile
Risk Priority 65 floored blend · peak EPSS

Summary

CVE-2024-6890 is a high-severity Use of Hard-coded Cryptographic Key (CWE-321) vulnerability in Journyx Journyx. Its CVSS base score is 8.8 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Brute Force (T1110); ranked in the top 49% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

The strongest mitigations our analysis identified map to AC-10 (Concurrent Session Control) and AC-7 (Unsuccessful Logon Attempts) — see the control section below for these in your framework.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1110 Brute Force Credential Access
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
T1499.002 Service Exhaustion Flood Impact
Adversaries may target the different network services provided by systems to conduct a denial of service (DoS).
T1499.003 Application Exhaustion Flood Impact
Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications.
T1552 Unsecured Credentials Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials.
T1552.001 Credentials In Files Credential Access
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
T1552.004 Private Keys Credential Access
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2024-6892Same product: Journyx Journyx
CVE-2024-6891Same product: Journyx Journyx
CVE-2024-6893Same product: Journyx Journyx
CVE-2025-9004Shared CWE-799
CVE-2025-8927Shared CWE-799
CVE-2025-12547Shared CWE-799
CVE-2025-1629Shared CWE-799
CVE-2025-7882Shared CWE-799
CVE-2026-10216Shared CWE-799
CVE-2025-3556Shared CWE-799

Affected Assets

journyx
journyx
11.5.4

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

Requiring cryptographic keys to be established and managed according to defined requirements prevents developers from embedding static unchangeable keys.

ac-10 enforces a hard limit on concurrent sessions per user, directly stopping uncontrolled interaction frequency at the session level.

ac-7 directly enforces a limit on the frequency of invalid authentication attempts, structurally preventing the weakness for that interaction class.

Authenticator management requires secure distribution and handling of credentials, structurally discouraging hard-coded values.

sc-5 reduces the impact of excessive request volume (DoS) but does not itself impose the frequency controls whose absence defines the weakness.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure-SDLC activities such as code review and secret scanning directly prevent embedding static keys.

PR.AA-01 partial match
prevents

PR.AA-01's credential/key-management processes can reduce the incentive to embed secrets but do not address or detect hard-coded values in source code, so the weakness remains fully possible.

PR.AA-03 partial match
prevents

Authentication mechanisms often depend on random values (nonces, tokens), so the control can reduce exposure but eliminating the CWE does not achieve authentication outcomes.

PR.DS-01 partial match
prevents

Data-at-rest protection policies require proper key management and therefore discourage hard-coded keys.

PR.DS-02 partial match
prevents

Data-in-transit protection similarly depends on non-hard-coded keys for encryption.

PR.IR-01 partial match
prevents

Protecting networks from unauthorized usage can incorporate rate limiting to bound interaction frequency.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Cryptographic controls require adequate key/seed entropy, directly mitigating small random-value spaces.

finds

Security testing can detect insufficient randomness in tokens, session IDs, or keys.

prevents

Education on secure configuration practices discourages technical staff from embedding or relying on hard-coded credentials in systems and applications.

mitigates

Network security controls can enforce rate limiting and throttling at the perimeter.

prevents

Application security requirements explicitly include controls on interaction frequency and throttling.

prevents

Secure architecture principles recommend rate-limiting and resource-management mechanisms.

References