CVE-2021-41835
Summary
| CVE | CVE-2021-41835 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-21 19:15:00 UTC |
| Updated | 2022-01-27 19:26:00 UTC |
| Description | Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted service on Port TCP/80 to the encrypted service. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Fresenius-kabi | Agilia Connect | - | All | All | All |
| Operating System | Fresenius-kabi | Agilia Connect | All | All | All | All |
| Application | Fresenius-kabi | Agilia Partner Maintenance Software | All | All | All | All |
| Hardware | Fresenius-kabi | Link Agilia | - | All | All | All |
| Operating System | Fresenius-kabi | Link Agilia Firmware | All | All | All | All |
| Operating System | Fresenius-kabi | Link Agilia Firmware | 3.0 | - | All | All |
| Operating System | Fresenius-kabi | Link Agilia Firmware | 3.0 | d15 | All | All |
| Application | Fresenius-kabi | Vigilant Centerium | 1.0 | All | All | All |
| Application | Fresenius-kabi | Vigilant Insight | 1.0 | All | All | All |
| Application | Fresenius-kabi | Vigilant Mastermed | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fresenius Kabi Agilia Connect Infusion System | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Julian Suleder (ERNW Research GmbH), Nils Emmerich (ERNW Research GmbH), Raphael Pavlidis (ERNW Research GmbH), and Dr. Oliver Matula (ERNW Enno Rey Netzwerke GmbH) reported these vulnerabilities to the German Federal Office for Information Security (BSI) in the context of the BSI project ManiMed (Medical Device Manipulation Project).
There are currently no legacy QID mappings associated with this CVE.