Battelle's vulnerability profile centers on a narrowly scoped product portfolio, with exposure concentrated in the V2I Hub platform. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through application-layer weakness classes including SQL injection, cross-site scripting, improper privilege management, and insufficiently protected credentials, reflecting common risks in web-facing integration and data-handling software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Battelle over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000631CRITICAL Battelle V2I Hub 3.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tmx/TmxCtl/src/lib/PluginStatus.cpp and TmxControl::user_i | Dec 28, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-1000628CRITICAL Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the direct checking of the API key against a user-supplied value in PHP's GET global | Dec 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-1000627CRITICAL Battelle V2I Hub 2.5.1 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to the API key file. An attacker could exploit this v | Dec 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-1000626CRITICAL Battelle V2I Hub 2.5.1 could allow a remote attacker to bypass security restrictions, caused by the lack of requirement to change the default API key. An attacker could exploit thi | Dec 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-1000625CRITICAL Battelle V2I Hub 2.5.1 contains hard-coded credentials for the administrative account. An attacker could exploit this vulnerability to log in as an admin on any installation and ga | Dec 28, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-1000630HIGH Battelle V2I Hub 2.5.1 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to /api/PluginStatusActions.php and /status/plugi | Dec 28, 2018 | 7.2 | 25 | NO | NO |
CVE-2018-1000624HIGH Battelle V2I Hub 2.5.1 is vulnerable to a denial of service, caused by the failure to restrict access to a sensitive functionality. By visiting http://V2I_HUB/UI/powerdown.php, a r | Dec 28, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-1000629MEDIUM Battelle V2I Hub 2.5.1 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by api/SystemConfigActions.php?action=add and the index.php scrip | Dec 28, 2018 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Battelle.
Media articles that mention a CVE ID that affects a product developed by Battelle — matched by CVE ID, not by vendor name.