Security Advisory

CVE-2023-36654

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-12-12 00:00:00
Last updated 2024-08-02 16:52:54
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.