CVE-2024-6890
Exposed Creds in Journyx 11.5.4
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2024-6890 is a high-severity Use of Hard-coded Cryptographic Key (CWE-321) vulnerability in Journyx Journyx. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Brute Force (T1110); ranked in the top 49% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to AC-10 (Concurrent Session Control) and AC-7 (Unsuccessful Logon Attempts) — see the control section below for these in your framework.
OWASP Top 10 for Web (2025)
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-47879
Vulnerability Data
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Requiring cryptographic keys to be established and managed according to defined requirements prevents developers from embedding static unchangeable keys.
ac-10 enforces a hard limit on concurrent sessions per user, directly stopping uncontrolled interaction frequency at the session level.
ac-7 directly enforces a limit on the frequency of invalid authentication attempts, structurally preventing the weakness for that interaction class.
Authenticator management requires secure distribution and handling of credentials, structurally discouraging hard-coded values.
sc-5 reduces the impact of excessive request volume (DoS) but does not itself impose the frequency controls whose absence defines the weakness.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure-SDLC activities such as code review and secret scanning directly prevent embedding static keys.
PR.AA-01's credential/key-management processes can reduce the incentive to embed secrets but do not address or detect hard-coded values in source code, so the weakness remains fully possible.
Authentication mechanisms often depend on random values (nonces, tokens), so the control can reduce exposure but eliminating the CWE does not achieve authentication outcomes.
Data-at-rest protection policies require proper key management and therefore discourage hard-coded keys.
Data-in-transit protection similarly depends on non-hard-coded keys for encryption.
Protecting networks from unauthorized usage can incorporate rate limiting to bound interaction frequency.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Cryptographic controls require adequate key/seed entropy, directly mitigating small random-value spaces.
Security testing can detect insufficient randomness in tokens, session IDs, or keys.
Education on secure configuration practices discourages technical staff from embedding or relying on hard-coded credentials in systems and applications.
Network security controls can enforce rate limiting and throttling at the perimeter.
Application security requirements explicitly include controls on interaction frequency and throttling.
Secure architecture principles recommend rate-limiting and resource-management mechanisms.