Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pharmahelp Firmware CRITICAL 9.8
CVE-2022-45611

An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login informatio…

Mitigation only
Fix from $2,300 2023-08-22
Agilia Partner Maintenance Software CRITICAL 9.8
CVE-2021-43355

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authenticat…

Fix: 3.0+
Fix from $2,300 2022-01-21
Agilia Connect Firmware HIGH 8.8
CVE-2021-44464

Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in p…

Fix: 3.0+
Fix from $1,950 2022-01-21
Agilia Partner Maintenance Software HIGH 7.5
CVE-2021-41835

Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport…

Fix: 3.0+
Fix from $1,950 2022-01-21
Agilia Partner Maintenance Software HIGH 7.2
CVE-2021-33846

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with…

Fix: 3.0+
Fix from $1,950 2022-01-21
Agilia Connect Firmware MEDIUM 6.1
CVE-2021-33848

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker cou…

Fix: 3.0+
Fix from $1,600 2022-01-21
Agilia Connect Firmware CRITICAL 9.8
CVE-2021-23196

The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does n…

Fix: 3.0+
Fix from $2,300 2022-01-21
Agilia Partner Maintenance Software CRITICAL 9.8
CVE-2021-23233

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. …

Fix: 3.0+
Fix from $2,300 2022-01-21
Agilia Connect Firmware CRITICAL 9.1
CVE-2021-31562

The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessi…

Fix: 3.0+
Fix from $2,300 2022-01-21
Agilia Partner Maintenance Software HIGH 7.5
CVE-2021-23236

Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a …

Fix: 3.0+
Fix from $1,950 2022-01-21
Agilia Connect MEDIUM 5.5
CVE-2021-23207

An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant Ma…

Fix: 3.0+
Fix from $1,600 2022-01-21
Agilia Sp Mc Wifi Firmware MEDIUM 5.3
CVE-2021-33843

Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An attacker may use this function…

Mitigation only
Fix from $1,600 2022-01-21
Agilia Connect Firmware MEDIUM 5.3
CVE-2021-23195

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. Whe…

Fix: 3.0+
Fix from $1,600 2022-01-21