CVE-2021-23233 HIGH

CVE-2021-23233: Fresenius Kabi Agilia Connect Infusion System

Vendor Fresenius Kabi
Product Agilia Link+
Weakness CWE-284
Published January 21, 2022
Last update April 16, 2025

CVSS base score

7.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

Key dates

02Disclosure timeline

January 21, 2022 CVE published
April 16, 2025 Record updated