CVE-2021-44207

Published Dec 21, 2021

Last updated a month ago

Overview

Description
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.9
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
6.8
Impact score
6.4
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:P

Known exploits

Data from CISA

Vulnerability name
Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
Exploit added on
Dec 23, 2024
Exploit action due
Jan 13, 2025
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.

Weaknesses

nvd@nist.gov
CWE-798
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-798

Social media

Hype score
Not currently trending

Configurations