CVE-2021-33843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
21/01/2022
Last modified:
27/10/2022

Description

Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this functionality to change the exposed configuration values such as network settings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fresenius-kabi:agilia_sp_mc_wifi_firmware:*:*:*:*:*:*:*:* d25 (including)
cpe:2.3:h:fresenius-kabi:agilia_sp_mc_wifi:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools