Lucene search

K
cvelistIcscertCVELIST:CVE-2021-33843
HistoryJan 21, 2022 - 6:17 p.m.

CVE-2021-33843 Fresenius Kabi Agilia Connect Infusion System files or directories accessible to external parties

2022-01-2118:17:41
CWE-552
icscert
www.cve.org
3
cve-2021-33843
fresenius kabi agilia connect
infusion system
default configuration
authentication
network settings

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

31.4%

Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.

CNA Affected

[
  {
    "product": "Agilia Connect WiFi ",
    "vendor": "Fresenius Kabi",
    "versions": [
      {
        "lessThan": "D25",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

31.4%

Related for CVELIST:CVE-2021-33843