📦 Cryptospike

by Prolion

🔍 What is Cryptospike?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36649

CRITICAL CVSS 9.1 Dec 12, 2023

CVE-2023-36649 allows attackers to obtain JWT tokens from Grafana logs or Loki REST API in ProLion CryptoSpike 3.0.15P2. With these tokens, attackers can impersonate legitimate users in web management...

CVE-2023-36655

CRITICAL CVSS 9.8 Dec 6, 2023

This vulnerability allows remote blocked users to bypass authentication in ProLion CryptoSpike when using LDAP/Active Directory. Attackers can obtain valid authentication tokens by manipulating userna...

CVE-2023-36647

HIGH CVSS 7.5 Dec 12, 2023

CVE-2023-36647 is a critical authentication bypass vulnerability in ProLion CryptoSpike where a hard-coded private key allows attackers to forge JWT tokens. This enables complete impersonation of any ...

CVE-2023-36651

HIGH CVSS 7.2 Dec 12, 2023

CVE-2023-36651 is a critical authentication bypass vulnerability in ProLion CryptoSpike 3.0.15P2 where hard-coded super-admin credentials allow remote attackers to gain full administrative access to t...