PT-2023-25658 · Prolion · Prolion Cryptospike
CVE-2023-36655
·
Publicado
2023-12-06
·
Atualizado
2024-10-11
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ProLion CryptoSpike version 3.0.15P2
Description
The issue concerns the login REST API when using LDAP or Active Directory as the user store. It allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combinations.
Recommendations
For ProLion CryptoSpike version 3.0.15P2, consider temporarily restricting access to the login REST API until a patch is available, or apply configuration changes to enforce case-sensitive username validation to minimize the risk of exploitation.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Prolion Cryptospike