NA

CVE-2023-36654

Published: 12/12/2023 Updated: 13/12/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated malicious users to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

prolion cryptospike 3.0.15