PT-2018-9478 · Battelle · Battelle V2I Hub
Published
2018-12-28
·
Updated
2019-01-11
·
CVE-2018-1000625
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Battelle V2I Hub version 2.5.1
Description
The issue concerns hard-coded credentials for the administrative account. An attacker could exploit this to log in as an admin on any installation and gain unauthorized access to the system.
Recommendations
For version 2.5.1, consider changing the default administrative credentials to unique, strong passwords to prevent unauthorized access. As a temporary workaround, restrict access to the administrative account until a patch is available.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Battelle V2I Hub