PT-2018-9479 · Battelle · Battelle V2I Hub
Published
2018-12-28
·
Updated
2019-10-03
·
CVE-2018-1000626
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Battelle V2I Hub version 2.5.1
Description
The issue is caused by the lack of requirement to change the default API key, allowing a remote attacker to bypass security restrictions. An attacker could exploit this to gain unauthorized access to the system by using all available API functions containing an unchanged API key.
Recommendations
For version 2.5.1, change the default API key to prevent unauthorized access. As a temporary workaround, consider restricting access to API functions that use the default API key until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Battelle V2I Hub