Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Prolion

First CVE: Dec 6, 2023Active for: 3 yearsTotal CVEs: 9

Prolion's vulnerability footprint centers on CryptoSpike, a niche cryptographic or security appliance product, with a durable signal dominated by authentication and data-access weaknesses. Vulnerabilities affecting this vendor skew toward serious outcomes, reaching critical severity across recurrent weakness classes including improper authentication, hard-coded credentials, path traversal, SQL injection, and integrity-validation bypass. Defenders should prioritize patches for this vendor's appliance tier, particularly where network or administrative exposure is present; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
9.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Prolion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2023
2 years ago
Most Recent CVE
Dec 12, 2023
955 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-36655CRITICAL
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication tok
Dec 6, 20239.829NONO
CVE-2023-36649CRITICAL
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management
Dec 12, 20239.127NONO
CVE-2023-36646HIGH
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve
Dec 12, 20238.826NONO
CVE-2023-36648HIGH
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny
Dec 12, 20238.225NONO
CVE-2023-36647HIGH
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in we
Dec 12, 20237.524NONO
CVE-2023-36651HIGH
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoint
Dec 12, 20237.223NONO
CVE-2023-36650HIGH
A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update p
Dec 12, 20237.222NONO
CVE-2023-36654MEDIUM
Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated
Dec 12, 20236.521NONO
CVE-2023-36652MEDIUM
A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in th
Dec 12, 20234.316NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
56%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (33.3%)
High2 (22.2%)
None4 (44.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Prolion.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Prolion — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Prolion's Products

View all 1 CNAs →

Top CWEs