Umbra Wiki cve cve/CVE-2021-44207
Back to wiki

CVE-2021-44207 — Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

provenance: imported · CVE: CVE-2021-44207

CVE-2021-44207: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Acclaim Systems
Product USAHERDS
Date added 2024-12-23
Due date 2025-01-13
Ransomware campaign use Unknown

Description

Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.

Notes

https://www.acclaimsystems.com/#contact ; https://www.tnatc.org/#contact ; https://nvd.nist.gov/vuln/detail/CVE-2021-44207

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-44207
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog