SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1000626

Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key.

CRITICAL 9.8EPSS 2.85%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key. An attacker could exploit this vulnerability using all available API functions containing an unchanged API key to gain unauthorized access to the system.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.85% probability · 86th percentile
CISA KEV
Not listed
Affected
battelle/v2i hub
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.