Site icon TheCyberThrone

CISA adds Acclaim Flaw CVE-2021-44207 to KEV Catalog

Advertisements

The US CISA has added new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation

CVE-2021-44207: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

CVE-2021-44207 with a CVSS score of 8.1 affecting Acclaim Systems USAHERDS software versions up to and including 7.4.0.1. The vulnerability arises from the use of hard-coded credentials within the software. Hard-coded credentials refer to usernames, passwords, or cryptographic keys embedded directly into the code. These credentials are usually meant for initial setup or debugging purposes but can become a significant security risk if not removed before deployment. In the case of CVE-2021-44207, attackers with knowledge of these embedded credentials can exploit the system to gain unauthorized access.

Advertisements

Impact: The presence of hard-coded credentials can have severe consequences:

Advertisements

Vendor Advisory

Acclaim Systems has issued an advisory concerning this vulnerability. They recommend that users update the latest version of the software, which addresses the hard-coded credentials issue and enhances security. Following the vendor’s guidance is crucial for ensuring the system’s integrity and security.

CISA has set January 13, 2025, as a deadline for federal agencies to remediate the vulnerability

Exit mobile version