CVE-2021-44207
8.1HIGHAcclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
Veröffentlicht: 12/21/2021Aktualisiert: 11/10/2025
CISA Bekannte Ausgenutzte Schwachstelle
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.
Erforderliche Maßnahme:
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.
Fälligkeitsdatum:
2025-01-13
Beschreibung
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
KI-AnalyseKI-gestützt
Betroffene Produkte
acclaimsystemsusaherds
Referenzen
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.mdThird Party Advisory
- https://www.acclaimsystems.comVendor Advisory
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.mdThird Party Advisory
- https://www.acclaimsystems.comVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44207US Government Resource