CISA Adds Acclaim USAHERDS Vulnerability to KEV Catalog Amid Active Exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44207 | Hard-Coded Credentials in Acclaim Systems USAHERDS (through 7.4.0.1) CVE-2021-44207 is a use of hard-coded credentials (CWE-798) in Acclaim Systems USAHERDS through version 7.4.0.1. Because built-in credentials are embedded in the application rather than provisioned per deployment, a remote attacker who learns or extracts them can authenticate to the system over the network with no privileges and no user interaction (CVSS 3.1: 8.1, high attack complexity). Successful abuse gives the attacker unauthorized authenticated access to USAHERDS and its data, providing a foothold in the hosting environment that has been used in active exploitation. Affected organizations are those running USAHERDS up to and including 7.4.0.1 — a niche government-sector web application rather than a mass-market product — so exposure is concentrated in a small number of agency deployments. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-23 citing active exploitation, and EPSS currently assigns a 17.6% probability of exploitation in the next 30 days (97th percentile). Do: Per the CISA KEV required action, apply mitigations per vendor instructions — contact Acclaim Systems for a supported fix or mitigation — or discontinue use of the product if mitigations are unavailable (federal agencies must act within two weeks of the 2024-12-23 KEV addition per BOD 22-01). In the meantime, restrict network exposure of USAHERDS to trusted users only and review authentication logs for unexpected logins, especially with built-in/service accounts, since the hard-coded credentials cannot be rotated by administrators alone. No public proof-of-concept is known, but active exploitation is confirmed, so treat any USAHERDS instance reachable from the internet as at risk. | 8.1 | 18% | KEV |
| nichelikely tens to low hundreds of deployments (estimated; no public install counts available) | |
| CVE-2024-53961 | ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data. Exploitation of this issue requires the admin panel be exposed to the internet. NVD description · AI analysis pending | 8.1 | 14% |
| — |
Full article368 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 24, 2024Vulnerability / Software Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched high-severity security flaw impacting Acclaim Systems USAHERDS to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild.
The vulnerability in question is CVE-2021-44207 (CVSS score: 8.1), a case of hard-coded, static credentials in Acclaim USAHERDS that could allow an attacker to ultimately execute arbitrary code on susceptible servers.
Specifically, it concerns the use of static ValidationKey and DecryptionKey values in version 7.4.0.1 and prior that could be weaponized to achieve remote code execution on the server that runs the application. That said, an attacker would have to leverage some other means to obtain the keys in the first place.
"These keys are used to provide security for the application ViewState," Google-owned Mandiant said in advisory for the flaw back in December 2021. "A threat actor with knowledge of these keys can trick the application server into deserializing maliciously crafted ViewState data."
"A threat actor with knowledge of the validationKey and decryptionKey for a web application can construct a malicious ViewState that passes the MAC check and will be deserialized by the server. This deserialization can result in the execution of code on the server."
While there are no new reports of CVE-2021-44207 being weaponized in real-world attacks, the vulnerability was identified as being abused by the China-linked APT41 threat actor back in 2021 as a zero-day as part of attacks targeting six U.S. state government networks.
Federal Civilian Executive Branch (FCEB) agencies are recommended to apply vendor-provided mitigations by January 13, 2025, to safeguard their networks against active threats.
The development comes as Adobe warned of a critical security flaw in ColdFusion (CVE-2024-53961, CVSS score: 7.8), which it said already has a known proof-of-concept (PoC) exploit that could cause an arbitrary file system read.
The vulnerability has been addressed in ColdFusion 2021 Update 18 and ColdFusion 2023 Update 12. Users are advised to apply the patches as soon as possible to mitigate potential risks.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/cisa-adds-acclaim-usaherds.html