{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2021-44207",
  "revision": 1,
  "title": "Acclaim USAHERDS — hardcoded credentials in the application",
  "summary": "The animal health records application (Acclaim USAHERDS) through 7.4.0.1 ships fixed credentials, and an attacker who obtains the framework key through another route turns that into code running on the server.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.1,
    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.17578,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "high",
    "kev_added": "2024-12-23",
    "prerequisites": "The framework key, obtained separately, plus network access to the application."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1078"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade past 7.4.0.1 and rotate the framework key now; state agencies run this, so also review accounts and recent record changes.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-44207",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2021-44207",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-44207",
      "retrieved_at": "2026-09-24T12:03:01.274Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44207",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.acclaimsystems.com"
    },
    {
      "type": "writeup",
      "url": "https://github.com/mandiant/Vulnerability-Disclosures/blob/master/MNDT-2021-0012/MNDT-2021-0012.md"
    }
  ],
  "published_at": "2021-12-21T18:15:08.143Z",
  "issued_at": "2026-09-24T12:03:01.274Z",
  "tags": [
    "acclaim",
    "usaherds",
    "hardcoded-credentials",
    "government",
    "kev"
  ]
}
