Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    2
    Critical Level Threats
    5
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-36654

    Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2023

    CVE-2023-36647

    A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

    Last Modified: Nov 26, 2024
    Published: Dec 12, 2023

    CVE-2023-36648

    Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2023

    CVE-2023-36649

    Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2023

    CVE-2023-36650

    A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update packages.

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2023
    Items Per Page
    Prolion Vulnerabilities & Security CVEs | CVE-DB