7.5
CVSSv2

CVE-2021-23233

Published: 21/01/2022 Updated: 28/01/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fresenius-kabi agilia partner maintenance software

fresenius-kabi vigilant centerium 1.0

fresenius-kabi vigilant insight 1.0

fresenius-kabi vigilant mastermed 1.0

fresenius-kabi agilia_connect_firmware

fresenius-kabi link\\+_agilia_firmware

fresenius-kabi link\\+_agilia_firmware 3.0