CVE-2021-44207Patch(acclaimsystems / usaherds)

LOWCVSS 8.1 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch acclaimsystems usaherds systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-01-13. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation.

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • usaherds

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
usaherds

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 102-09
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2021-44207 : USAHERDS HARD-CODED CREDENTIALS ADMINISTRATIVE BACKDOOR ALERT 🚨 Acclaim USAHERDS A critical unauthenticated authentication bypass vulnerability exists in USAHERDS due to hard-coded administrative credentials embedded directly in the application, enabling attackers to fully bypass access controls and gain permanent administrator access. Risk Severity: Critical (unauthenticated admin access, trivial exploitability, high-value government target, emergency patching required) Impact: • Full administrative system compromise • Unauthorized access to sensitive veterinary disease surveillance databases • Ability to modify, delete, or falsify outbreak reports and diagnostic records • Disruption of multi-state emergency agricultural response coordination • Lateral movement into USDA APHIS and state government networks • Audit log manipulation to conceal malicious activity Root Cause: CWE-798 (Use of Hard-coded Credentials) The authentication module contains static administrator credentials embedded directly in the application code, enabling unconditional authentication bypass. Attackers can: • Authenticate remotely using embedded credentials • Bypass all access controls • Gain full system administrator privileges • Exfiltrate sensitive epidemiological intelligence • Manipulate disease outbreak data • Pivot deeper into connected government infrastructure Are You Affected? Vulnerable: • Acclaim USAHERDS versions through 7.4.0.1 Fixed in: • USAHERDS 7.4.0.2 and later (patched releases available from Acclaim) Immediate Action Required: Update/Patch: • Upgrade immediately to USAHERDS 7.4.0.2+ and verify removal of hard-coded credential logic. Mitigation (if you cannot patch within hours): • Restrict access to USAHERDS systems using strict IP allowlisting • Block external access to administrative endpoints • Enforce VPN-only administrative access Audit & Monitor: • Review authentication logs for abnormal admin login patterns • Monitor for unauthorized data modifications and suspicious outbound connections • Validate integrity of surveillance and outbreak records Incident Response: • If exposed and exploitation is suspected, isolate the host, preserve forensic artifacts, audit administrative accounts, and verify all epidemiological data for tampering. Given USAHERDS’ critical role in national biosecurity and public health, this administrative backdoor represents a high-impact blast-radius event. Patch immediately and assume compromise if exposure existed. 🛡️

    Post summary

    CVE‑2021‑44207 is a critical authentication bypass due to hard‑coded credentials in USAHERDS, fully mitigated by upgrading to version 7.4.0.2+, with recommended temporary mitigations.

    0000090
    581 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appacclaimsystemsusaherds---

Explore more