ZeroHour

CVE-2023-36650

PoC
CVSS 3.1
7.2 high
EPSS
<1%p33
Published
()
Modified
Description

A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers to execute OS commands as the root Linux user on the host system via forged update packages.

Vendors
prolion
Products
cryptospike
Weakness
CWE-354
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.