NA

CVE-2023-36651

Published: 12/12/2023 Updated: 14/12/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote malicious users to login to web management as super-admin and consume the most privileged REST API endpoints via these credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

prolion cryptospike 3.0.15