MEDIUM · 5.9

CVE-2021-33846

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possess...

Vulnerability Description

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possession of the key can issue valid JWTs and impersonate arbitrary users.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
Fresenius-KabiAgilia Partner Maintenance Software<= 3.3.0
Fresenius-KabiVigilant Centerium1.0
Fresenius-KabiVigilant Insight1.0
Fresenius-KabiVigilant Mastermed1.0
Fresenius-KabiAgilia Connect Firmware<= d25
Fresenius-KabiAgilia Connect-
Fresenius-KabiLink\+ Agilia Firmware< 3.0
Fresenius-KabiLink\+ Agilia-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-33846?

CVE-2021-33846 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possess...

How severe is CVE-2021-33846?

CVE-2021-33846 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-33846?

Check the references section above for vendor advisories and patch information. Affected products include: Fresenius-Kabi Agilia Partner Maintenance Software, Fresenius-Kabi Vigilant Centerium, Fresenius-Kabi Vigilant Insight, Fresenius-Kabi Vigilant Mastermed, Fresenius-Kabi Agilia Connect Firmware.