ZeroHour

CVE-2021-44207

KEVniche

Hard-Coded Credentials in Acclaim Systems USAHERDS (through 7.4.0.1)

CISA: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

CVSS 3.1
8.1 high
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2021-44207 is a use of hard-coded credentials (CWE-798) in Acclaim Systems USAHERDS through version 7.4.0.1. Because built-in credentials are embedded in the application rather than provisioned per deployment, a remote attacker who learns or extracts them can authenticate to the system over the network with no privileges and no user interaction (CVSS 3.1: 8.1, high attack complexity). Successful abuse gives the attacker unauthorized authenticated access to USAHERDS and its data, providing a foothold in the hosting environment that has been used in active exploitation. Affected organizations are those running USAHERDS up to and including 7.4.0.1 — a niche government-sector web application rather than a mass-market product — so exposure is concentrated in a small number of agency deployments. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-23 citing active exploitation, and EPSS currently assigns a 17.6% probability of exploitation in the next 30 days (97th percentile).

What to do: Per the CISA KEV required action, apply mitigations per vendor instructions — contact Acclaim Systems for a supported fix or mitigation — or discontinue use of the product if mitigations are unavailable (federal agencies must act within two weeks of the 2024-12-23 KEV addition per BOD 22-01). In the meantime, restrict network exposure of USAHERDS to trusted users only and review authentication logs for unexpected logins, especially with built-in/service accounts, since the hard-coded credentials cannot be rotated by administrators alone. No public proof-of-concept is known, but active exploitation is confirmed, so treat any USAHERDS instance reachable from the internet as at risk.

Affected
Acclaim Systems USAHERDSthrough 7.4.0.1 (all versions up to and including 7.4.0.1)
Estimated exposure
nichelikely tens to low hundreds of deployments (estimated; no public install counts available) — USAHERDS is a specialized government web application (used for animal-health reporting by U.S. state/territory agriculture agencies per public reporting) deployed once per agency rather than distributed at scale, so the installed base is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

CISA Known Exploited Vulnerability
Affected
Acclaim Systems USAHERDS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.
Due date
Ransomware use
Unknown
Vendors
acclaimsystems
Products
usaherds
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news