PT-2022-11492 · Fresenius Kabi · Agilia Link+
Published
2022-01-21
·
Updated
2022-01-27
·
CVE-2021-41835
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fresenius Kabi Agilia Link + version 3.0
Description
The issue concerns the lack of enforcement of transport layer encryption, which may result in transmitted data being sent in cleartext. Although transport layer encryption is available on Port TCP/443, the affected service does not automatically redirect from the unencrypted service on Port TCP/80 to the encrypted service.
Recommendations
For Fresenius Kabi Agilia Link + version 3.0, consider configuring the service to perform an automated redirect from Port TCP/80 to Port TCP/443 to ensure encryption of transmitted data. As a temporary workaround, restrict access to the unencrypted service on Port TCP/80 to minimize the risk of exploitation.
Fix
Use of a Broken Cryptographic Algorithm
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Agilia Link+