PT-2022-11492 · Fresenius Kabi · Agilia Link+

Published

2022-01-21

·

Updated

2022-01-27

·

CVE-2021-41835

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fresenius Kabi Agilia Link + version 3.0
Description The issue concerns the lack of enforcement of transport layer encryption, which may result in transmitted data being sent in cleartext. Although transport layer encryption is available on Port TCP/443, the affected service does not automatically redirect from the unencrypted service on Port TCP/80 to the encrypted service.
Recommendations For Fresenius Kabi Agilia Link + version 3.0, consider configuring the service to perform an automated redirect from Port TCP/80 to Port TCP/443 to ensure encryption of transmitted data. As a temporary workaround, restrict access to the unencrypted service on Port TCP/80 to minimize the risk of exploitation.

Fix

Use of a Broken Cryptographic Algorithm

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41835

Affected Products

Agilia Link+