PT-2018-9477 · Battelle · Battelle V2I Hub

Publicado

2018-12-28

·

Atualizado

2019-10-03

·

CVE-2018-1000624

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Battelle V2I Hub version 2.5.1
Description The issue is caused by the failure to restrict access to a sensitive functionality, allowing a remote attacker to shut down the system. This can be exploited by visiting the "http://V2I HUB/UI/powerdown.php" API endpoint.
Recommendations For Battelle V2I Hub version 2.5.1, restrict access to the powerdown.php functionality to prevent unauthorized shutdowns of the system. Consider implementing proper access controls to sensitive functionalities to mitigate the risk of exploitation.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000624

Produtos afetados

Battelle V2I Hub