PT-2018-9479 · Battelle · Battelle V2I Hub

Publicado

2018-12-28

·

Atualizado

2019-10-03

·

CVE-2018-1000626

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Battelle V2I Hub version 2.5.1
Description The issue is caused by the lack of requirement to change the default API key, allowing a remote attacker to bypass security restrictions. An attacker could exploit this to gain unauthorized access to the system by using all available API functions containing an unchanged API key.
Recommendations For version 2.5.1, change the default API key to prevent unauthorized access. As a temporary workaround, consider restricting access to API functions that use the default API key until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-1000626

Produtos afetados

Battelle V2I Hub