PT-2018-9479 · Battelle · Battelle V2I Hub

Published

2018-12-28

·

Updated

2019-10-03

·

CVE-2018-1000626

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Battelle V2I Hub version 2.5.1
Description The issue is caused by the lack of requirement to change the default API key, allowing a remote attacker to bypass security restrictions. An attacker could exploit this to gain unauthorized access to the system by using all available API functions containing an unchanged API key.
Recommendations For version 2.5.1, change the default API key to prevent unauthorized access. As a temporary workaround, consider restricting access to API functions that use the default API key until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-1000626

Affected Products

Battelle V2I Hub