CVE-2021-44207
acclaimsystems usaherds
Published 21 Dec 2021 · updated 17 Jun 2026 · Analyzed
8.1 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 23 Dec 2024, with a remediation deadline of 13 Jan 2025 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.
Description
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
References
- github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.md · Third Party Advisory
- www.acclaimsystems.com/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44207 · US Government Resource