CVE-2021-23195
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the directory will be displayed, allowing an attacker to identify and access files on the server.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to d25 |
| Running on/with | Platform Versions |
|---|---|
Fresenius Kabi Agilia Connect | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.0 | |
| Version 1.0 | |
| Version 1.0 | |
| Version 1.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0 |
| Running on/with | Platform Versions |
|---|---|
Fresenius Kabi Link+ Agilia | All versions |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-548
Exposure of Information Through Directory Listing
A directory listing is inappropriately exposed, yielding potentially sensitive information to attackers.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.