CVE-2021-44207 describes a critical hard-coded credentials vulnerability in Acclaim USAHERDS software versions through 7.4.0.1. This flaw allows unauthenticated attackers to gain full control over affected systems remotely with high impact on confidentiality, integrity, and availability. It carries a CVSS score of 8.1 (HIGH) and is actively exploited in the wild, notably by APT41 targeting U.S. state government networks. Despite no public exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion and media attention, indicating its widespread awareness and potential for continued exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.4.0.1CPE matchmatch criteria | cpe:2.3:a:acclaimsystems:usaherds:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.