Prolion's vulnerability footprint centers on CryptoSpike, a niche cryptographic or security appliance product, with a durable signal dominated by authentication and data-access weaknesses. Vulnerabilities affecting this vendor skew toward serious outcomes, reaching critical severity across recurrent weakness classes including improper authentication, hard-coded credentials, path traversal, SQL injection, and integrity-validation bypass. Defenders should prioritize patches for this vendor's appliance tier, particularly where network or administrative exposure is present; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prolion over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36655CRITICAL The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication tok | Dec 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-36649CRITICAL Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management | Dec 12, 2023 | 9.1 | 27 | NO | NO |
CVE-2023-36646HIGH Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to execute privileged functions and achieve | Dec 12, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-36648HIGH Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny | Dec 12, 2023 | 8.2 | 25 | NO | NO |
CVE-2023-36647HIGH A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in we | Dec 12, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-36651HIGH Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consume the most privileged REST API endpoint | Dec 12, 2023 | 7.2 | 23 | NO | NO |
CVE-2023-36650HIGH A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update p | Dec 12, 2023 | 7.2 | 22 | NO | NO |
CVE-2023-36654MEDIUM Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated | Dec 12, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-36652MEDIUM A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in th | Dec 12, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prolion.
Media articles that mention a CVE ID that affects a product developed by Prolion — matched by CVE ID, not by vendor name.