AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-36648

HIGH · CVSS 8.2 EPSS 0.98%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-12-12 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.2. It affects Apache. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2023-36648
Severity
HIGH
CVSS
8.2
EPSS
0.98%
Apache

Original NVD Description

Missing authentication in the internal data streaming system in ProLion CryptoSpike 3.0.15P2 allows remote unauthenticated users to read potentially sensitive information and deny service to users by directly reading and writing data in Apache Kafka (as consumer and producer).

Related CVEs

Other vulnerabilities affecting the same vendor(s)