Vulnerability CVE-2021-23233


Published: 2022-01-21

Description:
Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

Type:

CWE-798

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Fresenius-kabi -> Agilia partner maintenance software 
Fresenius-kabi -> Vigilant centerium 
Fresenius-kabi -> Vigilant insight 
Fresenius-kabi -> Vigilant mastermed 

 References:
https://www.cisa.gov/uscert/ics/advisories/icsma-21-355-01

Copyright 2022, cxsecurity.com

 

Back to Top