The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.
History

Tue, 18 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Aenrich a\+hrd
CPEs cpe:2.3:a:aenrich:a\+hrd:*:*:*:*:*:*:*:*
Vendors & Products Aenrich a\+hrd

Wed, 12 Nov 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Aenrich
Aenrich a+hrd
Vendors & Products Aenrich
Aenrich a+hrd

Wed, 12 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 07:45:00 +0000

Type Values Removed Values Added
Description The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.
Title aEnrich|a+HRD - Authentication Abuse
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2025-11-12T07:38:30.394Z

Updated: 2025-11-12T17:01:46.367Z

Reserved: 2025-11-07T11:10:59.934Z

Link: CVE-2025-12871

cve-icon Vulnrichment

Updated: 2025-11-12T17:01:46.367Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-12T08:15:41.733

Modified: 2025-11-18T18:28:18.553

Link: CVE-2025-12871

cve-icon Redhat

No data.