Fresenius Kabi's vulnerability footprint centers on a portfolio of infusion, clinical nutrition, and hospital logistics software products, including platforms such as Agilia Connect, Agilia Partner Maintenance Software, Vigilant Centerium, Vigilant Insight, and Vigilant MasterMed that support medication delivery and patient-care workflows in healthcare settings. The vendor's disclosures reflect the connectivity and data-handling demands of medical-device integration and hospital IT infrastructure, where access control and configuration management are central to operational security. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fresenius Kabi over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23233CRITICAL Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests t | Jan 21, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-23196CRITICAL The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attri | Jan 21, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-43355CRITICAL Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server s | Jan 21, 2022 | 9.8 | 29 | NO | NO |
CVE-2021-31562CRITICAL The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An attac | Jan 21, 2022 | 9.1 | 27 | NO | NO |
CVE-2021-44464HIGH Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across all instances. An attacker in possession of the password may g | Jan 21, 2022 | 8.8 | 26 | NO | NO |
CVE-2021-23236HIGH Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressin | Jan 21, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-45611CRITICAL An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information. | Aug 22, 2023 | 9.8 | 24 | NO | NO |
CVE-2021-41835HIGH Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on | Jan 21, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-33846HIGH Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticated users that are signed with a symmetric encryption key. An | Jan 21, 2022 | 7.2 | 23 | NO | NO |
CVE-2021-33848MEDIUM Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker could inject JavaScript in a GET p | Jan 21, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fresenius Kabi.
Media articles that mention a CVE ID that affects a product developed by Fresenius Kabi — matched by CVE ID, not by vendor name.