U.S. CISA adds Acclaim Systems USAHERDS flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44207 | Hard-Coded Credentials in Acclaim Systems USAHERDS (through 7.4.0.1) CVE-2021-44207 is a use of hard-coded credentials (CWE-798) in Acclaim Systems USAHERDS through version 7.4.0.1. Because built-in credentials are embedded in the application rather than provisioned per deployment, a remote attacker who learns or extracts them can authenticate to the system over the network with no privileges and no user interaction (CVSS 3.1: 8.1, high attack complexity). Successful abuse gives the attacker unauthorized authenticated access to USAHERDS and its data, providing a foothold in the hosting environment that has been used in active exploitation. Affected organizations are those running USAHERDS up to and including 7.4.0.1 — a niche government-sector web application rather than a mass-market product — so exposure is concentrated in a small number of agency deployments. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-23 citing active exploitation, and EPSS currently assigns a 17.6% probability of exploitation in the next 30 days (97th percentile). Do: Per the CISA KEV required action, apply mitigations per vendor instructions — contact Acclaim Systems for a supported fix or mitigation — or discontinue use of the product if mitigations are unavailable (federal agencies must act within two weeks of the 2024-12-23 KEV addition per BOD 22-01). In the meantime, restrict network exposure of USAHERDS to trusted users only and review authentication logs for unexpected logins, especially with built-in/service accounts, since the hard-coded credentials cannot be rotated by administrators alone. No public proof-of-concept is known, but active exploitation is confirmed, so treat any USAHERDS instance reachable from the internet as at risk. | 8.1 | 18% | KEV |
| nichelikely tens to low hundreds of deployments (estimated; no public install counts available) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 7.4.0.1 | vulnerability, it impacts Acclaim USAHERDS web application 7.4.0.1 and earlier. An attacker who knows static ValidationKey and |
Full article335 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 23, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acclaim Systems USAHERDS flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Acclaim Systems USAHERDS vulnerability, tracked as CVE-2021-44207 (CVSS score: 8.1) to its Known Exploited Vulnerabilities (KEV) catalog.
USAHERDS, developed by Acclaim Systems, is a web-based application designed to assist U.S. state governments in tracking and managing animal health and disease outbreaks. It is part of the AgraGuard suite of products, which includes USAHERDS, USALIMS, USAPlants, USAFoodSafety, and USAMeals, aimed at supporting agricultural and food safety operations.
The vulnerability was exploited by the Chinese cyber-espionage group APT41 to breach multiple U.S. state government networks.
The flaw stems from the use of hard-coded credentials vulnerability, it impacts Acclaim USAHERDS web application 7.4.0.1 and earlier. An attacker who knows static ValidationKey and DecryptionKey values can exploit them to execute arbitrary code on the system that runs the application.
Attackers can craft malicious ViewState data to bypass MAC checks, and trigger server-side code execution.
“The Acclaim USAHERDS web application 7.4.0.1 and Earlier, builds prior to November 2021, used static ValidationKey and DecryptionKey values.” reads the advisory. “High – Knowledge of the ValidationKey and DecryptionKey can be used to achieve Remote Code Execution on the system that runs the application.”
Security researchers Douglas Bienstock from Mandiant reported the issue to the company. Acclaim Systems addressed this issue by releasing a patch in November 2021 to remediate the vulnerability.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by January 13, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172255/hacking/u-s-cisa-acclaim-systems-usaherds-flaw-known-exploited-vulnerabilities-catalog.html