CVE-2021-23196
21.01.2022, 19:15
The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.Enginsight
Vendor | Product | Version |
---|---|---|
fresenius-kabi | agilia_partner_maintenance_software | 𝑥 ≤ 3.3.0 |
fresenius-kabi | vigilant_centerium | 1.0 |
fresenius-kabi | vigilant_insight | 1.0 |
fresenius-kabi | vigilant_mastermed | 1.0 |
fresenius-kabi | link\+_agilia_firmware | 𝑥 < 3.0 |
fresenius-kabi | link\+_agilia_firmware | 3.0 |
fresenius-kabi | link\+_agilia_firmware | 3.0:d15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.