Lucene search

K
cveMitreCVE-2023-36655
HistoryDec 06, 2023 - 4:15 p.m.

CVE-2023-36655

2023-12-0616:15:07
CWE-287
mitre
web.nvd.nist.gov
11
cve-2023-36655
prolion cryptospike
rest api
authentication bypass
ldap
active directory
remote user
security vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

43.4%

The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.

Affected configurations

Nvd
Node
prolioncryptospikeMatch3.0.15p2
VendorProductVersionCPE
prolioncryptospike3.0.15cpe:2.3:a:prolion:cryptospike:3.0.15:p2:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.4

Confidence

High

EPSS

0.001

Percentile

43.4%

Related for CVE-2023-36655