CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.
CVE
CVE-2023-36647
Severity
HIGH
CVSS
7.5
EPSS
0.75%
Original NVD Description
A hard-coded cryptographic private key used to sign JWT authentication tokens in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate arbitrary users and roles in web management and REST API endpoints via crafted JWT tokens.
Related CVEs
Other vulnerabilities affecting the same vendor(s)