MEDIUM · 6.5

CVE-2021-23207

An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate...

Vulnerability Description

An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by impersonating users.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Fresenius-KabiAgilia Connect<= d25
Fresenius-KabiAgilia Partner Maintenance Software<= 3.3.0
Fresenius-KabiVigilant Centerium1.0
Fresenius-KabiVigilant Insight1.0
Fresenius-KabiVigilant Mastermed1.0
Fresenius-KabiLink\+ Agilia Firmware< 3.0
Fresenius-KabiLink\+ Agilia-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-23207?

CVE-2021-23207 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate...

How severe is CVE-2021-23207?

CVE-2021-23207 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-23207?

Check the references section above for vendor advisories and patch information. Affected products include: Fresenius-Kabi Agilia Connect, Fresenius-Kabi Agilia Partner Maintenance Software, Fresenius-Kabi Vigilant Centerium, Fresenius-Kabi Vigilant Insight, Fresenius-Kabi Vigilant Mastermed.