Lucene search

K
cvelistIcscertCVELIST:CVE-2021-23195
HistoryJan 21, 2022 - 6:17 p.m.

CVE-2021-23195 Fresenius Kabi Agilia Connect Infusion System exposure of information through directory listing

2022-01-2118:17:38
CWE-548
icscert
www.cve.org
5
fresenius kabi
agilia connect
infusion system
information exposure
directory listing
vigilant software suite
mastermed dashboard
automated indexing
web server
attacker
server access

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

31.4%

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the directory will be displayed, allowing an attacker to identify and access files on the server.

CNA Affected

[
  {
    "product": "Vigilant Software Suite (Mastermed Dashboard)",
    "vendor": "Fresenius Kabi",
    "versions": [
      {
        "lessThan": "2.0.1.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

31.4%

Related for CVELIST:CVE-2021-23195