CVE-2021-44207
high · 8.1Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.
Added 2024-12-23Remediation due 2025-01-13
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
8.1
CVSS
17.6%
EPSS (exploit prob.)
97th
EPSS percentile
2021-12-21
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-798
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| acclaimsystems | usaherds | <= 7.4.0.1 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.md
- https://www.acclaimsystems.com
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.md
- https://www.acclaimsystems.com
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44207
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-44207