Vulnerability record · CVE-2021-44207 · published 21 December 2021
CVE-2021-44207: Acclaim USAHERDS hard-coded credentials allow remote compromise
Acclaimsystems · Usaherds
Acclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the application without legitimate access. Because the flaw is baked into the product, it cannot be fixed by configuration alone and requires a vendor patch or compensating controls.
Description
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with a high EPSS percentile and CVSS 8.1, but exploitation requires knowledge of the static credentials and the record provides no patched version or confirmed active campaign details.
What it is
Acclaim USAHERDS through 7.4.0.1 ships with hard-coded credentials (CWE-798). Anyone who knows or extracts those credentials can authenticate to the application without legitimate access. Because the flaw is baked into the product, it cannot be fixed by configuration alone and requires a vendor patch or compensating controls.
Impact
An attacker gains authenticated access to USAHERDS with the privileges tied to the hard-coded account, with high confidentiality, integrity and availability impact per the CVSS vector. That access can be used to read or alter animal health and herd records and to disrupt the service.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), so an attacker only needs network access to the exposed USAHERDS interface and knowledge of the static credentials. Attack complexity is rated high (AC:H), meaning some additional condition or knowledge is needed beyond simple reachability.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2024-12-23, indicating real-world exploitation; EPSS is 0.17578 (96.98th percentile), a high relative likelihood. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor's patch or mitigation guidance for USAHERDS; contact Acclaim Systems for the fixed release since the record does not name a patched version.
- If no fix is available, discontinue use of the product or isolate it from untrusted networks per CISA's required action.
- Restrict network access to USAHERDS to trusted management networks and require strong authentication in front of it.
- Rotate or disable any default or hard-coded accounts and audit for their use.
- Monitor vendor and CISA advisories for updated remediation guidance.
Detection
- Search authentication logs for logins using known or default USAHERDS service accounts, especially from unexpected source IPs or outside business hours.
- Baseline normal account usage and alert on first-seen accounts or authentication from new geographies or hosts.
- Review network logs for direct access to USAHERDS management interfaces from the internet or untrusted segments.
- Correlate successful authentications with subsequent record modification or export activity in USAHERDS.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-44207 to the Known Exploited Vulnerabilities catalog on 23 December 2024 as "Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please contact the product developer for support and vulnerability mitigation. Federal deadline 13 January 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.md | Third Party Advisory |
| https://www.acclaimsystems.com | Vendor Advisory |
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.md | Third Party Advisory |
| https://www.acclaimsystems.com | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-44207 | US Government Resource |
Track CVE-2021-44207 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44207), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.