CVE-2021-33846
21.01.2022, 19:15
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possession of the key can issue valid JWTs and impersonate arbitrary users.Enginsight
Vendor | Product | Version |
---|---|---|
fresenius-kabi | agilia_partner_maintenance_software | 𝑥 ≤ 3.3.0 |
fresenius-kabi | vigilant_centerium | 1.0 |
fresenius-kabi | vigilant_insight | 1.0 |
fresenius-kabi | vigilant_mastermed | 1.0 |
fresenius-kabi | link\+_agilia_firmware | 𝑥 < 3.0 |
fresenius-kabi | link\+_agilia_firmware | 3.0 |
fresenius-kabi | link\+_agilia_firmware | 3.0:d15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration