← Vulnerability feed

Vulnerability record · CVE-2021-44207 · published 21 December 2021

CVE-2021-44207: Acclaim USAHERDS hard-coded credentials allow remote compromise

Acclaimsystems · Usaherds

Acclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the application without legitimate access. Because the flaw is baked into the product, it cannot be fixed by configuration alone and requires a vendor patch or compensating controls.

8.1 CVSS 3.1 High CISA KEV since 23 Dec 2024 EPSS 18% · top 3.0% CWE-798 · Hard-coded credentials
8.1CVSS 3.1 base score, v2 6.8
18%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with a high EPSS percentile and CVSS 8.1, but exploitation requires knowledge of the static credentials and the record provides no patched version or confirmed active campaign details.

What it is

Acclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the application without legitimate access. Because the flaw is baked into the product, it cannot be fixed by configuration alone and requires a vendor patch or compensating controls.

Impact

An attacker gains authenticated access to USAHERDS with the privileges tied to the hard-coded account, with high confidentiality, integrity and availability impact per the CVSS vector. That access can be used to read or alter animal health and herd records and to disrupt the service.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), so an attacker only needs network access to the exposed USAHERDS interface and knowledge of the static credentials. Attack complexity is rated high (AC:H), meaning some additional condition or knowledge is needed beyond simple reachability.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2024-12-23, indicating real-world exploitation; EPSS is 0.17578 (96.98th percentile), a high relative likelihood. No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor's patch or mitigation guidance for USAHERDS; contact Acclaim Systems for the fixed release since the record does not name a patched version.
  • If no fix is available, discontinue use of the product or isolate it from untrusted networks per CISA's required action.
  • Restrict network access to USAHERDS to trusted management networks and require strong authentication in front of it.
  • Rotate or disable any default or hard-coded accounts and audit for their use.
  • Monitor vendor and CISA advisories for updated remediation guidance.

Detection

  • Search authentication logs for logins using known or default USAHERDS service accounts, especially from unexpected source IPs or outside business hours.
  • Baseline normal account usage and alert on first-seen accounts or authentication from new geographies or hosts.
  • Review network logs for direct access to USAHERDS management interfaces from the internet or untrusted segments.
  • Correlate successful authentications with subsequent record modification or export activity in USAHERDS.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-44207 to the Known Exploited Vulnerabilities catalog on 23 December 2024 as "Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation. Federal deadline 13 January 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-44207 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed9.8CVE-2025-30406Gladinet CentreStack hardcoded machineKey deserialization RCEGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) uses a hardcoded machineKey in the portal's web.config, allowing deserializ…KEVEPSS 94%analysed9.8CVE-2024-20439Cisco Smart Licensing Utility hard-coded admin credential allows remote loginCisco Smart Licensing Utility (CSLU) contains an undocumented static credential for an administrative account. An unauthenticated remote attacker who…KEVEPSS 97%analysed9.1CVE-2024-28987SolarWinds Web Help Desk hardcoded credential flawSolarWinds Web Help Desk contains a hardcoded credential vulnerability (CWE-798) that lets a remote, unauthenticated attacker reach internal function…KEVEPSS 93%analysed9.8CVE-2024-3272D-Link NAS Devices Hard-Coded Credentials in nas_sharing.cgiD-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'u…KEVEPSS 98%analysed9.8CVE-2023-6448Unitronics VisiLogic default admin password in Vision and Samba PLCs/HMIsUnitronics VisiLogic before 9.9.00, used with Vision and Samba PLCs and HMIs, ships with a default administrative password. Because the credential is…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2021-44207), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.