CVE-2023-36647

HIGH

ProLion CryptoSpike 3.0.15P2 - Auth Bypass

Title source: llm
STIX 2.1

Description

A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.

References (1)

Core 1
Core References
Exploit, Third Party Advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36647

Scores

CVSS v3 7.5
EPSS 0.0075
EPSS Percentile 50.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
prolion/cryptospike 3.0.15 p2
Published Dec 12, 2023
Tracked Since Feb 18, 2026