CVE-2023-36647
Last modified
CVE-2023-36647 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Prolion | Cryptospike | 3.0.15 | P2 |
References
- https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36647Exploit, Third Party Advisory
- https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36647Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-36647?
How severe is CVE-2023-36647?
How do I fix CVE-2023-36647?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-36641A numeric truncation error in Fortinet FortiProxy version 7.…6.5
- CVE-2023-36642An improper neutralization of special elements used in an OS…7.8
- CVE-2023-36643Incorrect Access Control in ITB-GmbH TradePro v9.5, allows r…5.3
- CVE-2023-36644Incorrect Access Control in ITB-GmbH TradePro v9.5, allows r…5.3
- CVE-2023-36645SQL injection vulnerability in ITB-GmbH TradePro v9.5, allow…9.8
- CVE-2023-36646Incorrect user role checking in multiple REST API endpoints …8.8
- CVE-2023-36648Missing authentication in the internal data streaming system…8.2
- CVE-2023-36649Insertion of sensitive information in the centralized (Grafa…9.1
- CVE-2023-3665 A code injection vulnerability in Trellix ENS 10.7.0 April …7.8
- CVE-2023-36650A missing integrity check in the update system in ProLion Cr…7.2
- CVE-2023-36651Hidden and hard-coded credentials in ProLion CryptoSpike 3.0…7.2
- CVE-2023-36652A SQL Injection in the users searching REST API endpoint in …4.3
Are you affected by CVE-2023-36647?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
