Vulnerabilities > Fresenius Kabi > Agilia Connect

DATE CVE VULNERABILITY TITLE RISK
2022-01-21 CVE-2021-23207 Insufficiently Protected Credentials vulnerability in Fresenius-Kabi products
An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users.
local
low complexity
fresenius-kabi CWE-522
2.1
2022-01-21 CVE-2021-41835 Cleartext Transmission of Sensitive Information vulnerability in Fresenius-Kabi products
Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption.
network
low complexity
fresenius-kabi CWE-319
5.0