CVE Published: 21/01/2022 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: icscert |
Vendor: Fresenius Kabi |
Product: Vigilant Software Suite (Mastermed Dashboard) Status : PUBLISHED
CVE-2021-33846 Description
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An attacker in possession of the key can issue valid JWTs and impersonate arbitrary users.
Metrics
CVSS Version: 3.1 |
Base Score: 5.9 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* NETWORK Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* UNCHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-327 CWE Name: CWE-327 Use of a Broken or Risky Cryptographic Algorithm Source: Fresenius Kabi
Common Attack Pattern Enumeration and Classification (CAPEC)