Medium severity6.5NVD Advisory· Published Jan 21, 2022· Updated Jun 17, 2026
CVE-2021-23207
CVE-2021-23207
Description
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by impersonating users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:a:fresenius-kabi:agilia_partner_maintenance_software:*:*:*:*:*:*:*:*Range: <=3.3.0
- cpe:2.3:a:fresenius-kabi:vigilant_centerium:1.0:*:*:*:*:*:*:*
- cpe:2.3:a:fresenius-kabi:vigilant_insight:1.0:*:*:*:*:*:*:*
cpe:2.3:a:fresenius-kabi:vigilant_mastermed:1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fresenius-kabi:vigilant_mastermed:1.0:*:*:*:*:*:*:*
- (no CPE)range: = 2.0.1.3
cpe:2.3:o:fresenius-kabi:link\+_agilia_firmware:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fresenius-kabi:link\+_agilia_firmware:*:*:*:*:*:*:*:*range: <3.0
- cpe:2.3:o:fresenius-kabi:link\+_agilia_firmware:3.0:-:*:*:*:*:*:*
- cpe:2.3:o:fresenius-kabi:link\+_agilia_firmware:3.0:d15:*:*:*:*:*:*
- Fresenius Kabi/Agilia Partnerv5Range: unspecified
- Range: unspecified
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsma-21-355-01nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.