The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
History

Tue, 18 Nov 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Aenrich a\+hrd
CPEs cpe:2.3:a:aenrich:a\+hrd:*:*:*:*:*:*:*:*
Vendors & Products Aenrich a\+hrd

Wed, 12 Nov 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Aenrich
Aenrich a+hrd
Vendors & Products Aenrich
Aenrich a+hrd

Wed, 12 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 07:45:00 +0000

Type Values Removed Values Added
Description The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.
Title aEnrich|eHRD - Authentication Abuse
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2025-11-12T07:35:43.207Z

Updated: 2025-11-12T17:02:29.442Z

Reserved: 2025-11-07T11:10:58.835Z

Link: CVE-2025-12870

cve-icon Vulnrichment

Updated: 2025-11-12T17:02:29.442Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-12T08:15:41.513

Modified: 2025-11-18T19:31:34.847

Link: CVE-2025-12870

cve-icon Redhat

No data.