CVE-2023-36647

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
12/12/2023
Last modified:
14/12/2023

Description

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prolion:cryptospike:3.0.15:p2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools