Lucene search

K
cvelistIcscertCVELIST:CVE-2021-23233
HistoryJan 21, 2022 - 6:17 p.m.

CVE-2021-23233 Fresenius Kabi Agilia Connect Infusion System

2022-01-2118:17:37
CWE-284
icscert
www.cve.org
2
fresenius kabi
agilia connect
infusion system
authentication bypass
sensitive endpoints
critical actions
configuration parameters

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

9.7

Confidence

High

EPSS

0.002

Percentile

57.0%

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

CNA Affected

[
  {
    "product": "Agilia Link+",
    "vendor": "Fresenius Kabi",
    "versions": [
      {
        "lessThan": "3.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

9.7

Confidence

High

EPSS

0.002

Percentile

57.0%

Related for CVELIST:CVE-2021-23233