EXPOSURES › CVE-2021-44207
CVE-2021-44207
HIGH ⌖ ON CISA KEV · EXPLOITEDAcclaim Systems USAHERDS shipped with hard-coded credentials enabling remote code execution, a critical flaw exploited in the wild.
The USAHERDS application shipped with hard-coded credentials that allowed attackers to achieve remote code execution without needing the MachineKey, bypassing standard authentication controls. This flaw is actively exploited in the wild and poses a severe risk to DIB organizations relying on Acclaim Systems hardware for FedRAMP compliance, as it undermines the integrity of the security controls required for handling sensitive data.
Shame score — Hard-coded credentials enabling RCE is a negligent, avoidable design flaw that directly compromises system integrity and is actively being exploited by threat actors.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be obtained via a separate vulnerability or other channel.