Skip to main content

Vendor/product archive

prolion / cryptospike CVEs

Beta · best-effort

9 CVEs tagged to prolion / cryptospike2 Critical, 5 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-36654

Published Dec 12, 2023

Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associate…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36652

Published Dec 12, 2023

A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36651

Published Dec 12, 2023

Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoin…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36650

Published Dec 12, 2023

A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36649

Published Dec 12, 2023

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36648

Published Dec 12, 2023

Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36647

Published Dec 12, 2023

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36646

Published Dec 12, 2023

Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achiev…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36655

Published Dec 6, 2023

The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1