CVE-2021-44207
KEVnicheHard-Coded Credentials in Acclaim Systems USAHERDS (through 7.4.0.1)
CISA: Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability
CVE-2021-44207 is a use of hard-coded credentials (CWE-798) in Acclaim Systems USAHERDS through version 7.4.0.1. Because built-in credentials are embedded in the application rather than provisioned per deployment, a remote attacker who learns or extracts them can authenticate to the system over the network with no privileges and no user interaction (CVSS 3.1: 8.1, high attack complexity). Successful abuse gives the attacker unauthorized authenticated access to USAHERDS and its data, providing a foothold in the hosting environment that has been used in active exploitation. Affected organizations are those running USAHERDS up to and including 7.4.0.1 — a niche government-sector web application rather than a mass-market product — so exposure is concentrated in a small number of agency deployments. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-23 citing active exploitation, and EPSS currently assigns a 17.6% probability of exploitation in the next 30 days (97th percentile).
What to do: Per the CISA KEV required action, apply mitigations per vendor instructions — contact Acclaim Systems for a supported fix or mitigation — or discontinue use of the product if mitigations are unavailable (federal agencies must act within two weeks of the 2024-12-23 KEV addition per BOD 22-01). In the meantime, restrict network exposure of USAHERDS to trusted users only and review authentication logs for unexpected logins, especially with built-in/service accounts, since the hard-coded credentials cannot be rotated by administrators alone. No public proof-of-concept is known, but active exploitation is confirmed, so treat any USAHERDS instance reachable from the internet as at risk.
| Acclaim Systems USAHERDS | through 7.4.0.1 (all versions up to and including 7.4.0.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
- Affected
- Acclaim Systems USAHERDS
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.
- Due date
- Ransomware use
- Unknown
- Vendors
- acclaimsystems
- Products
- usaherds
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H