Junglewise Threat Intelligence

CVE-2021-44207: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

CVE-2021-44207 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2024-12-23

Executive brief

Acclaim Systems USAHERDS through version 7.4.0.1 contains hard-coded credentials. An attacker who obtains the MachineKey through separate means can exploit this to achieve remote code execution on the system running the application.

Affected products

  • Acclaim Systems USAHERDS up to and including 7.4.0.1

Timeline

  • 2021-12-21: disclosed: NVD Published Date
  • 2024-12-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog