Security readout for executives and security teams
Plain-English summary
This flaw affects the Agilia Link+ infusion system web application. The application does not adequately protect authentication details and relies on client-side authentication/session controls, creating risk that an attacker with network access could bypass intended protections and affect confidentiality, integrity, or availability.
Executive priority
Treat as high priority for environments using Agilia Link+ because the weakness concerns authentication protection in a medical device support system. Confirm whether the product is deployed before escalating operational changes.
Technical view
CVE-2021-23196 is a CWE-522 issue in Fresenius Kabi Agilia Link+ where authentication attributes are insufficiently protected and authentication/session management are implemented exclusively client-side. The CVSS 3.1 score is 7.3 with network attack vector, low complexity, and no required privileges or user interaction.
Likely exposure
Exposure is most relevant where Agilia Link+ web application instances, specifically version 3.0 per the description, are reachable over a network. The bundle does not provide deployment prevalence, internet exposure data, or complete affected version detail.
Exploitation context
The source bundle does not cite active exploitation, and KEV is false. The CVSS vector indicates a remotely reachable, low-complexity issue requiring no privileges or user interaction, but no exploit availability is established by the supplied evidence.
Researcher notes
Evidence is limited to the CVE description, CVSS data, CWE-522 classification, and the CISA ICS advisory reference. Do not assume affected versions beyond the supplied Agilia Link+ information or claim exploitation without additional cited evidence.
Mitigation direction
- Check Fresenius Kabi and CISA advisory guidance for approved updates or workarounds.
- Limit network reachability to the Agilia Link+ web application where operationally feasible.
- Place compensating access controls in front of exposed management or web interfaces.
- Review clinical network segmentation for systems communicating with Agilia Link+.
- Prioritize remediation according to medical device risk management procedures.
Validation and detection
- Inventory Fresenius Kabi Agilia Link+ deployments and record software versions.
- Confirm whether any Agilia Link+ version 3.0 web application is network reachable.
- Review access paths from enterprise, guest, vendor, and clinical networks.
- Check vendor and CISA advisory status for current remediation instructions.
- Document compensating controls if immediate vendor remediation is unavailable.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-522: Credential and account abuse lookup
Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-23196 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L3.93.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.3HighVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Source materials
- CVE List V5 sourceCVE List V5
- https://www.cisa.gov/uscert/ics/advisories/icsma-21-355-01CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Insufficiently Protected Credentials
Insufficiently Protected Credentials represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
