Vulnerability CVE-2021-23195


Published: 2022-01-21

Description:
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the directory will be displayed, allowing an attacker to identify and access files on the server.

Type:

CWE-200

(Information Exposure)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Fresenius-kabi -> Agilia partner maintenance software 
Fresenius-kabi -> Vigilant centerium 
Fresenius-kabi -> Vigilant insight 
Fresenius-kabi -> Vigilant mastermed 

 References:
https://www.cisa.gov/uscert/ics/advisories/icsma-21-355-01

Copyright 2022, cxsecurity.com

 

Back to Top