VulnerabilityModified
CVE-2018-1000626
Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key.
CRITICAL 9.8EPSS 2.85%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key. An attacker could exploit this vulnerability using all available API functions containing an unchanged API key to gain unauthorized access to the system.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.85% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- battelle/v2i hub
- Source
- cve@mitre.org
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/147303Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/147303Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.