CVE-2021-23233
Summary
| CVE | CVE-2021-23233 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-21 19:15:00 UTC |
| Updated | 2022-01-28 15:48:00 UTC |
| Description | Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Fresenius-kabi | Agilia Connect | - | All | All | All |
| Operating System | Fresenius-kabi | Agilia Connect Firmware | All | All | All | All |
| Application | Fresenius-kabi | Agilia Partner Maintenance Software | All | All | All | All |
| Hardware | Fresenius-kabi | Link Agilia | - | All | All | All |
| Operating System | Fresenius-kabi | Link Agilia Firmware | All | All | All | All |
| Operating System | Fresenius-kabi | Link Agilia Firmware | 3.0 | - | All | All |
| Operating System | Fresenius-kabi | Link Agilia Firmware | 3.0 | d15 | All | All |
| Application | Fresenius-kabi | Vigilant Centerium | 1.0 | All | All | All |
| Application | Fresenius-kabi | Vigilant Insight | 1.0 | All | All | All |
| Application | Fresenius-kabi | Vigilant Mastermed | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fresenius Kabi Agilia Connect Infusion System | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Julian Suleder (ERNW Research GmbH), Nils Emmerich (ERNW Research GmbH), Raphael Pavlidis (ERNW Research GmbH), and Dr. Oliver Matula (ERNW Enno Rey Netzwerke GmbH) reported these vulnerabilities to the German Federal Office for Information Security (BSI) in the context of the BSI project ManiMed (Medical Device Manipulation Project).
There are currently no legacy QID mappings associated with this CVE.