İçeriğe atla
Noroxi

prolion kayıtları

prolion üreticisine ait 9 yayımlanmış kayıt.

Tüm kayıtlar

9 kayıt
  • CVE-2023-36655
    39İzleyin

    The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user t

    KritikCVSS 9,8İstismar yokEPSS %1

    prolion · cryptospike6 Ara 2023

  • CVE-2023-36649
    36İzleyin

    Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to im

    KritikCVSS 9,1İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36646
    35İzleyin

    Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to

    YüksekCVSS 8,8İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36648
    32İzleyin

    Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read pot

    YüksekCVSS 8,2İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36647
    30İzleyin

    A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to imp

    YüksekCVSS 7,5İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36651
    28İzleyin

    Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consu

    YüksekCVSS 7,2İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36650
    28İzleyin

    A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux use

    YüksekCVSS 7,2İstismar yokEPSS %0

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36654
    26İzleyin

    Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download

    OrtaCVSS 6,5İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023

  • CVE-2023-36652
    17İzleyin

    A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read datab

    OrtaCVSS 4,3İstismar yokEPSS %1

    prolion · cryptospike11 Ara 2023