Vulnerabilities (CVE)

Filtered by vendor Prolion Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-36651 1 Prolion 1 Cryptospike 2023-12-14 N/A 7.2 HIGH
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoints via these credentials.
CVE-2023-36647 1 Prolion 1 Cryptospike 2023-12-14 N/A 7.5 HIGH
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.
CVE-2023-36650 1 Prolion 1 Cryptospike 2023-12-13 N/A 7.2 HIGH
A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update packages.
CVE-2023-36648 1 Prolion 1 Cryptospike 2023-12-13 N/A 8.2 HIGH
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).
CVE-2023-36646 1 Prolion 1 Cryptospike 2023-12-13 N/A 8.8 HIGH
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve privilege escalation via REST API endpoint invocation.