prolion kayıtları
prolion üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-798 Use of Hard-coded Credentials2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-532 Insertion of Sensitive Information into Log File1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-36655İstismar yok | The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user tprolion · cryptospike · CWE-287 | Kritik9,8 | — | %1,0 | 6 Ara 2023 |
36İzleyin | CVE-2023-36649İstismar yok | Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to improlion · cryptospike · CWE-532 | Kritik9,1 | — | %0,9 | 11 Ara 2023 |
35İzleyin | CVE-2023-36646İstismar yok | Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to prolion · cryptospike · CWE-863 | Yüksek8,8 | — | %0,8 | 11 Ara 2023 |
32İzleyin | CVE-2023-36648İstismar yok | Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potprolion · cryptospike · CWE-287 | Yüksek8,2 | — | %1,0 | 11 Ara 2023 |
30İzleyin | CVE-2023-36647İstismar yok | A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impprolion · cryptospike · CWE-798 | Yüksek7,5 | — | %0,8 | 11 Ara 2023 |
28İzleyin | CVE-2023-36651İstismar yok | Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consuprolion · cryptospike · CWE-798 | Yüksek7,2 | — | %1,0 | 11 Ara 2023 |
28İzleyin | CVE-2023-36650İstismar yok | A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux useprolion · cryptospike · CWE-354 | Yüksek7,2 | — | %0,4 | 11 Ara 2023 |
26İzleyin | CVE-2023-36654İstismar yok | Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download prolion · cryptospike · CWE-22 | Orta6,5 | — | %1,2 | 11 Ara 2023 |
17İzleyin | CVE-2023-36652İstismar yok | A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read databprolion · cryptospike · CWE-89 | Orta4,3 | — | %0,6 | 11 Ara 2023 |
- CVE-2023-3665539İzleyin
The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user t
KritikCVSS 9,8İstismar yokEPSS %1prolion · cryptospike6 Ara 2023
- CVE-2023-3664936İzleyin
Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to im
KritikCVSS 9,1İstismar yokEPSS %1prolion · cryptospike11 Ara 2023
- CVE-2023-3664635İzleyin
Incorrect user role checking in multiple REST API endpoints in ProLion CryptoSpike 3.0.15P2 allows a remote attacker with low privileges to
YüksekCVSS 8,8İstismar yokEPSS %1prolion · cryptospike11 Ara 2023
- CVE-2023-3664832İzleyin
Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read pot
YüksekCVSS 8,2İstismar yokEPSS %1prolion · cryptospike11 Ara 2023
- CVE-2023-3664730İzleyin
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to imp
YüksekCVSS 7,5İstismar yokEPSS %1prolion · cryptospike11 Ara 2023
- CVE-2023-3665128İzleyin
Hidden and hard-coded credentials in ProLion CryptoSpike 3.0.15P2 allow remote attackers to login to web management as super-admin and consu
YüksekCVSS 7,2İstismar yokEPSS %1prolion · cryptospike11 Ara 2023
- CVE-2023-3665028İzleyin
A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux use
YüksekCVSS 7,2İstismar yokEPSS %0prolion · cryptospike11 Ara 2023
- CVE-2023-3665426İzleyin
Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download
OrtaCVSS 6,5İstismar yokEPSS %1prolion · cryptospike11 Ara 2023
- CVE-2023-3665217İzleyin
A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read datab
OrtaCVSS 4,3İstismar yokEPSS %1prolion · cryptospike11 Ara 2023