No vendor instructions to follow — the one entry that points to the developer
For the hard-coded credentials flaw in Acclaim Systems USAHERDS, CISA asked for mitigations or discontinued use, then added a line asking readers to contact the product developer for support and mitigation.
Key facts
- CVE IDCVE-2021-44207
- Affected (vendor / product)Acclaim Systems USAHERDS
- CWECWE-798
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2025-01-13 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2021-44207 concerns the use of hard-coded credentials in Acclaim Systems USAHERDS.
- The credentials could carry an attacker through to running code remotely on whatever system the application sits on.
- The MachineKey has to come from somewhere else first, either another flaw or some other route, so this one does not stand alone.
- Beyond mitigating or stopping use, the instruction asks readers to get in touch with whoever develops the product, for help and for mitigating the flaw.
- Listed 23 December 2024 with a due date of 13 January 2025, a window of twenty-one days; of the 1,579 entries without an article this site holds as of 2026-09-05, 56 (3.5%) presuppose chaining.
1Told to follow instructions that are not there
This instruction opens in the standard way: put the mitigations on as the vendor directs, or stop using the product where none can be had. That is the pairing 252 entries share. Then a sentence is added. Get in touch with whoever develops the product, it says, for help and for mitigating the flaw.
2What the added line tells you
Told to follow vendor instructions, the entry cannot say where those instructions are. Hence the added sentence pointing at the developer. The standard pairing assumes that something exists to consult; where that assumption fails, the instruction has to hand the reader the bridge.
3The flaw carries a condition of its own
The description notes that the MachineKey has to come from somewhere else first, either another flaw or some other route. The flaw does not stand alone: it reaches remote code execution only in combination with something else.
A flaw that cannot stand alone is listed all the same. The test is that exploitation was observed; how complicated the preconditions are does not bear on whether an entry is made.
4The eight instructions side by side
| Form of instruction | What was asked | Entry |
|---|---|---|
| Narrowing the options | Only two remediations count, update or remove | Apache Log4j2, December 2021 |
| Setting an order | Block the traffic first, then update | Atlassian Confluence, June 2022 |
| When no fix exists | Mitigate as it becomes available; enable threat prevention meanwhile | Palo Alto PAN-OS, April 2024 |
| Determine and report | Establish whether compromised, report positives at once | Cisco IOS XE, October 2023 |
| Cutting what survives | Apply mitigations and kill every session | Citrix NetScaler, October 2023 |
| Conditions for return | Hunt, remediate, update, then return to service | Ivanti Connect Secure, January 2025 |
| Not fixing at all | Life has ended, so retire and replace | D-Link DIR-605, May 2024 |
| No reference to follow | Mitigate or stop, and go to the developer | Acclaim Systems USAHERDS, December 2024 |
Set out together, what shows is that the required action field serves as the place where whatever is particular to a flaw gets written down. For a majority, 889 entries, the single line about updates suffices. Reading what gets added when it does not is a way of reading what the flaw actually is.
Why it matters
The required action field serves as the place where whatever is particular to a flaw gets written down. A majority need only the line about applying updates; reading what is added when that will not do, whether narrowed options, an order, a report, killed sessions, conditions for return, retirement or a developer to contact, is a way of reading the flaw itself. The instruction grows specific exactly where the standard form breaks down.
FAQ
Why point to the developer?
What is the MachineKey?
Are flaws that cannot stand alone still listed?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).