Executive brief
Acclaim Systems USAHERDS through version 7.4.0.1 contains hard-coded credentials. An attacker who obtains the MachineKey through separate means can exploit this to achieve remote code execution on the system running the application.
Affected products
- Acclaim Systems USAHERDS up to and including 7.4.0.1
Timeline
- 2021-12-21: disclosed: NVD Published Date
- 2024-12-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog