Exploited Known exploited (KEV) CVE-2021-44207

No vendor instructions to follow — the one entry that points to the developer

Acclaim Systems USAHERDS Added to KEV Dec 23, 2024 Federal remediation due 2025-01-13

For the hard-coded credentials flaw in Acclaim Systems USAHERDS, CISA asked for mitigations or discontinued use, then added a line asking readers to contact the product developer for support and mitigation.

Key facts

  • CVE IDCVE-2021-44207
  • Affected (vendor / product)Acclaim Systems USAHERDS
  • CWECWE-798
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2025-01-13 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2021-44207 concerns the use of hard-coded credentials in Acclaim Systems USAHERDS.
  • The credentials could carry an attacker through to running code remotely on whatever system the application sits on.
  • The MachineKey has to come from somewhere else first, either another flaw or some other route, so this one does not stand alone.
  • Beyond mitigating or stopping use, the instruction asks readers to get in touch with whoever develops the product, for help and for mitigating the flaw.
  • Listed 23 December 2024 with a due date of 13 January 2025, a window of twenty-one days; of the 1,579 entries without an article this site holds as of 2026-09-05, 56 (3.5%) presuppose chaining.

1Told to follow instructions that are not there

This instruction opens in the standard way: put the mitigations on as the vendor directs, or stop using the product where none can be had. That is the pairing 252 entries share. Then a sentence is added. Get in touch with whoever develops the product, it says, for help and for mitigating the flaw.

2What the added line tells you

The aspectAn entry in the standard form, 252 of themThis entry, USAHERDS
First half of the instructionMitigate per vendor instructions, or discontinue useThe same
The added lineNoneGet in touch with whoever develops the product, for help and mitigation
What it impliesVendor instructions exist to be consultedThe reader must go and find them
Entries with this lineThe only one in these records

Told to follow vendor instructions, the entry cannot say where those instructions are. Hence the added sentence pointing at the developer. The standard pairing assumes that something exists to consult; where that assumption fails, the instruction has to hand the reader the bridge.

3The flaw carries a condition of its own

The description notes that the MachineKey has to come from somewhere else first, either another flaw or some other route. The flaw does not stand alone: it reaches remote code execution only in combination with something else.

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,57956 (3.5%) presuppose chaining with another flaw
Of those, descriptions presupposing an authenticated attacker31019.6%, against 227 (14.4%) stating unauthenticated
The window hereTwenty-one daysListed 23 December 2024, due 13 January 2025

A flaw that cannot stand alone is listed all the same. The test is that exploitation was observed; how complicated the preconditions are does not bear on whether an entry is made.

4The eight instructions side by side

Form of instructionWhat was askedEntry
Narrowing the optionsOnly two remediations count, update or removeApache Log4j2, December 2021
Setting an orderBlock the traffic first, then updateAtlassian Confluence, June 2022
When no fix existsMitigate as it becomes available; enable threat prevention meanwhilePalo Alto PAN-OS, April 2024
Determine and reportEstablish whether compromised, report positives at onceCisco IOS XE, October 2023
Cutting what survivesApply mitigations and kill every sessionCitrix NetScaler, October 2023
Conditions for returnHunt, remediate, update, then return to serviceIvanti Connect Secure, January 2025
Not fixing at allLife has ended, so retire and replaceD-Link DIR-605, May 2024
No reference to followMitigate or stop, and go to the developerAcclaim Systems USAHERDS, December 2024

Set out together, what shows is that the required action field serves as the place where whatever is particular to a flaw gets written down. For a majority, 889 entries, the single line about updates suffices. Reading what gets added when it does not is a way of reading what the flaw actually is.

Why it matters

The required action field serves as the place where whatever is particular to a flaw gets written down. A majority need only the line about applying updates; reading what is added when that will not do, whether narrowed options, an order, a report, killed sessions, conditions for return, retirement or a developer to contact, is a way of reading the flaw itself. The instruction grows specific exactly where the standard form breaks down.

FAQ

Why point to the developer?
The first half of the instruction is the standard line about following vendor instructions, but with no such instructions locatable, a sentence was added to bridge the gap.
What is the MachineKey?
The catalog states that exploiting this flaw requires it, and that it has to come from somewhere else first, either another flaw or some other route.
Are flaws that cannot stand alone still listed?
Yes. The test is that exploitation was observed; the complexity of the preconditions does not bear on listing.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.