ID

VAR-201812-0306


CVE

CVE-2018-1000625


TITLE

Battelle V2I Hub Vulnerabilities related to the use of hard-coded credentials

Trust: 0.8

sources: JVNDB: JVNDB-2018-013426

DESCRIPTION

Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and gain unauthorized access to the system. Battelle V2I Hub Contains a vulnerability in the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state

Trust: 1.71

sources: NVD: CVE-2018-1000625 // JVNDB: JVNDB-2018-013426 // VULMON: CVE-2018-1000625

IOT TAXONOMY

category:['network device']sub_category:hub

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:battellemodel:v2i hubscope:eqversion:2.5.1

Trust: 2.4

sources: JVNDB: JVNDB-2018-013426 // CNNVD: CNNVD-201812-1177 // NVD: CVE-2018-1000625

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-1000625
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-1000625
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201812-1177
value: CRITICAL

Trust: 0.6

VULMON: CVE-2018-1000625
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-1000625
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

nvd@nist.gov: CVE-2018-1000625
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULMON: CVE-2018-1000625 // JVNDB: JVNDB-2018-013426 // CNNVD: CNNVD-201812-1177 // NVD: CVE-2018-1000625

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.8

sources: JVNDB: JVNDB-2018-013426 // NVD: CVE-2018-1000625

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201812-1177

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201812-1177

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013426

PATCH

title:Top Pageurl:https://www.battelle.org/homepage

Trust: 0.8

sources: JVNDB: JVNDB-2018-013426

EXTERNAL IDS

db:NVDid:CVE-2018-1000625

Trust: 2.6

db:JVNDBid:JVNDB-2018-013426

Trust: 0.8

db:CNNVDid:CNNVD-201812-1177

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2018-1000625

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2018-1000625 // JVNDB: JVNDB-2018-013426 // CNNVD: CNNVD-201812-1177 // NVD: CVE-2018-1000625

REFERENCES

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/147302

Trust: 2.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-1000625

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-1000625

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/798.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2018-1000625 // JVNDB: JVNDB-2018-013426 // CNNVD: CNNVD-201812-1177 // NVD: CVE-2018-1000625

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2018-1000625
db:JVNDBid:JVNDB-2018-013426
db:CNNVDid:CNNVD-201812-1177
db:NVDid:CVE-2018-1000625

LAST UPDATE DATE

2025-01-30T19:54:31.677000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2018-1000625date:2019-01-11T00:00:00
db:JVNDBid:JVNDB-2018-013426date:2019-02-20T00:00:00
db:CNNVDid:CNNVD-201812-1177date:2018-12-29T00:00:00
db:NVDid:CVE-2018-1000625date:2024-11-21T03:40:15.740

SOURCES RELEASE DATE

db:VULMONid:CVE-2018-1000625date:2018-12-28T00:00:00
db:JVNDBid:JVNDB-2018-013426date:2019-02-20T00:00:00
db:CNNVDid:CNNVD-201812-1177date:2018-12-29T00:00:00
db:NVDid:CVE-2018-1000625date:2018-12-28T16:29:01.377