PT-2022-9382 · Fresenius Kabi · Agilia Link+
Dr. Oliver Matula
+3
·
Published
2022-01-21
·
Updated
2022-01-28
·
CVE-2021-23233
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fresenius Kabi Agilia Link+ versions 3.0 and prior
Description
The issue allows access to sensitive endpoints without requiring authentication information, such as a session cookie. This enables an attacker to send requests to these endpoints as an unauthenticated user, potentially performing critical actions or modifying critical configuration parameters.
Recommendations
For Fresenius Kabi Agilia Link+ versions 3.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Agilia Link+