CVE-2023-36647 is a high-severity vulnerability affecting ProLion CryptoSpike 3.0.15P2, stemming from a hard-coded cryptographic private key used for JWT authentication. This allows remote attackers to impersonate users and roles, leading to high integrity impact on web management and REST API endpoints. While no active exploitation or public exploit code is currently reported, the vulnerability has a CVSS score of 7.5 and a low EPSS score, indicating a lower likelihood of widespread exploitation despite its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.15CPE matchmatch criteria | cpe:2.3:a:prolion:cryptospike:3.0.15:p2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.